Motivation: Financial
Operators of the Phorpiex (Trik) worm and spam botnet active since ~2010, used to deliver malware and run extortion spam. A June 2018 misconfigured C2 server exposed 43M+ email addresses used for malspam distribution.
In June 2018 a misconfigured Trik C2 server exposed 43M+ email addresses used for malspam distribution (the Trik Spam Botnet breach in HIBP).
Attribution draws on public threat-intelligence reporting · Established (multi-source). Primary source →
Check your exposure privately, or request a tailored exposure audit.