FBI, CISA, and the Multi-State Information Sharing and Analysis Center (MS-ISAC) published a joint Phobos ransomware advisory on February 29, 2024. It describes reported attack methods, recommends defensive steps, and provides downloadable indicators of compromise (IOCs). The IOC tables reflect investigations from September through November 2023; the advisory separately says Phobos variants had been observed as recently as February 2024. Treat the indicators as dated investigation leads, not a live threat feed.
What Phobos ransomware is—and what the advisory covers
AA24-060A characterizes Phobos as ransomware-as-a-service (RaaS): a ransomware operation in which tools or services are used by affiliates or other actors to conduct attacks. MS-ISAC had regularly received reports of Phobos incidents affecting state, local, tribal, and territorial (SLTT) governments since May 2019. The advisory also identifies emergency services, education, public healthcare, and other critical-infrastructure organizations among the targets.
The agencies say the activity targeted these sectors to “successfully ransom several million U.S. dollars.” That is a qualitative, rounded statement in the joint advisory, not an exact victim count or a precise aggregate-ransom statistic. The agencies also say Phobos variants had been observed as recently as February 2024, citing open-source reporting. The IOC tables, by contrast, are attributed to FBI and CISA investigations conducted from September through November 2023.
The advisory discusses related variants named Elking, Eight, Devos, Backmydata, and Faust. FBI, CISA, and MS-ISAC describe their relationship to Phobos as likely based on similar tactics, techniques, and procedures (TTPs); that does not establish that every variant or intrusion is identical.
#1 Best Overall
How Phobos actors reportedly get in and operate
The advisory describes phishing and exposed or vulnerable Remote Desktop Protocol (RDP) services as access routes. Actors may scan for exposed RDP and use open-source brute-force tools against it. In another reported chain, spoofed email attachments carry hidden payloads such as SmokeLoader, which can download a Phobos payload and exfiltrate data.
Reported activity can extend beyond encrypting files. The advisory describes credential discovery, data theft, and deletion of Windows Volume Shadow Copies, which can make recovery harder. It names tools including Cobalt Strike and BloodHound, and reports use of WinSCP and Mega.io for exfiltration. Data targeted in observed incidents included legal and financial records, technical documents such as network architecture, and databases for common password-management software.
Rank #2
Phobos executables can encrypt connected logical drives. The advisory says actors used Windows tools such as vssadmin.exe and WMIC to find and delete shadow copies. These are behaviors documented in the advisory, not a complete inventory of every Phobos incident or a guarantee that a future intrusion will use the same tools.
Where to download the Phobos IOCs
AA24-060A provides IOC downloads in STIX XML and STIX JSON formats. Use the official advisory and its linked files to obtain the indicators:
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallRank #3
The advisory PDF lists the STIX XML file as 148 KB and the STIX JSON file as 120 KB. Those are the sizes stated in the document. Since the IOC tables are based on September–November 2023 investigations, use them as leads for detection and investigation and verify them against the official downloads. A match can support further investigation; by itself, an IOC match does not prove an organization is compromised or that the indicator is still active.
What defenders should do
The advisory’s three immediate recommendations address exposure, known weaknesses, and detection:
Rank #4
- Secure RDP ports. Reduce unnecessary RDP exposure and protect any RDP access the organization must retain. The advisory’s stated aim is to prevent threat actors from abusing RDP and related tools.
- Prioritize known exploited vulnerabilities. Use the CISA Known Exploited Vulnerabilities catalog to help prioritize remediation of vulnerabilities known to be exploited, rather than treating every patch as equally urgent.
- Implement endpoint detection and response (EDR). The advisory recommends EDR solutions to disrupt the memory-allocation techniques described in its technical analysis. Ensure endpoint coverage and alert handling include relevant behaviors, not only known file hashes.
Also plan for the possibility that attackers will try to remove recovery options after stealing data or encrypting systems. Because deleting shadow copies can impede restoration, maintain backups that attackers cannot readily alter and test restoration procedures. A backup is useful only if it is accessible when needed and restores the systems and data the organization depends on.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Reporting suspected Phobos activity in the United States
The advisory directs U.S. organizations to report suspicious or criminal activity to a local FBI field office or CISA’s 24/7 Operations Center. CISA lists Report@cisa.gov and (888) 282-0870 as contact options. When available, include the incident date and time, location, activity type, people affected, equipment involved, organization name, and a point of contact.
Recommended Free Tools
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

