A new variant of Phobos ransomware is reported to be linked to the popular malware sharing community VX-Underground, suggesting that the group is responsible for attacks using the encryptor.
See also: Rhysida ransomware behind the attack on the British Library?

Phobos was launched in 2018 and is believed to be a descendant of the Crysis, operating as a ransomware-as-a-service. In this mode, a group of threat actors manages the development of the ransomware and holds the translation key, while other threat actors act as collaborators to compromise networks and encrypt devices.
Although Phobos has been around for a long time, it never developed into an “elite” operation known for carrying out massive attacks and demanding millions of dollars. However, that doesn’t mean it isn’t a major operation, as it has widespread distribution through multiple affiliated threat actors and accounted for 4% of all submissions to the ID Ransomware service in 2023.
Recently, ransomware hunter PCrisk discovered a new variant of the Phobos ransomware that is trying to involve the VX-Underground community.
When encrypting files, the malware will append the string .id[[unique_id].[staff@vx-underground.org].VXUG, with the email being legitimate and the final extension 'VXUG,' indicating VX-Underground. When complete, Phobos will create two ransom notes on the Windows desktop and elsewhere.
The first is a ransom note named 'Buy Black Mass Volume II.txt', saying that the code is not “infected”, the code is used in all archived VX malware.
The second file is an HTA named 'Buy Black Mass Volume II.hta', which is a standard Phobos threat alert that has been customized to use the VX-Underground logo, name, and contact information. Black Mass is a book written by VX-Underground and sold on Amazon.
See also: Yamaha Motor: Ransomware attack led to employee data breach

VX-Underground is a malware community that includes a variety of different types of malware. It includes viruses, trojans, spyware, exploits, and more. The creators of VX-Underground are known for developing and distributing advanced forms of malware.
One of the common types of malware found on VX-Underground is viruses. Viruses are programs that copy themselves and spread from computer to computer by attaching themselves to other files or programs. Viruses can cause devastating effects on the victim's computer, such as file corruption or data loss.
Another common type of malware found on VX-Underground is trojans. Trojans are programs that exploit vulnerabilities in a computer's software or operating system to gain access or cause damage. They can be used to steal personal information, install other malware, or monitor user activity.
VX-Underground also includes spyware. Spyware collects information without the user's consent and sends it to a remote computer. This can include personal information, such as passwords or credit cards, and can pose a threat to the user's privacy and security .
See also: Toyota: Medusa ransomware gang threatens to leak data
Finally, VX-Underground also includes exploits. Exploits are small programs that exploit weaknesses in software or the operating system to gain access to a computer. These routines can be used by attackers to infiltrate a network or perform malicious actions, such as taking over a computer or installing other malware.
Source: bleepingcomputer
