According to a report by Cybereason, the new Phoenix keylogger that appeared on hacking forums over the summer has been linked to more than 10,000 infections.
First appearing in July, when it was released on HackForums, the keylogger gradually began to gain ground and is now considered one of the most significant threats.
Hackers have started using the Phoenix keylogger to carry out data theft campaigns. Researchers have identified numerous attackslinked to this keylogger.
Information theft
According to Cybereason researchers, the hacker behind Phoenix is very experienced and skilled. In just a few months, he evolved Phoenix from a simple keylogger into a multi-functional trojan infostealer
Initial versions were only capable of keylogging. However, more recent versions have the ability to steal data user passwords, from: 20 different browsers, 4 different email clients, FTP clients, and applications.
Most worryingly, however, Phoenix also has anti-AV and anti-VM features, which help it stay hidden so it cannot be detected and analyzed.
Both functions offer a list of processes that the Phoenix keylogger should terminate before continuing malicious activities.
This list includes more than 80 well-known security products and virtual machine (VM) technologies. These are used to detect and analyze suspicious programs. Therefore, disabling them is very dangerous.
In the image below you can see the list of products that the Phoenix keylogger disables:

Security products detect threats and alert users to any suspicious activity, but if Phoenix does its job properly, it will be able to collect the data it wants and send it to hackerswithout being noticed.
Credential theft
Cybereason researchers believe that the Phoenix keylogger is particularly popular because it is easy to use. It has also been observed that it is used in different configurations in different attacks, depending on the attacker's goal.
In most cases, the goal was to steal information, send it to the attackers, and then disappear from the system.
“Our assessment is that Phoenix is being used more for simple information theft, rather than as a tool designed for long-term surveillance,” said one researcher.
“Given that this is an entirely new malicious software that is evolving, there may be a change that will turn it into a more powerful surveillance tool in the future».
“As for the clientele, it seems that most buyers are interested in obtaining sensitive data that they could later sell on underground markets, mainly those related to credentials,” the researcher added.
The Phoenix keylogger can steal and send data to hackers within a few seconds. This is also the reason it is not used as a long‑term surveillance tool. It grabs the information it wants instantly.
Cybereason researchers believe that the creator of the Phoenix keylogger is also the creator of Alpha Keylogger, another malware that was discontinued a few months before Phoenix was released. The researchers link the two keyloggers because of their shared code and the similar way they were advertised on hacking forums.
