PhantomCore
PhantomCore is a suspected pro-Ukrainian / Ukraine-linked threat actor assessed by multiple cited reports as operating with Ukrainian interests in mind and targeting Russian and Belarusian organizations since 2022. Reporting describes PhantomCore as conducting cyber-espionage and later shifting at least part of its operations toward ransomware and destructive activity. The group has been linked to attacks against Russian and Belarusian companies across sectors, and one report linked it to compromises of 65 Microsoft Exchange servers in 26 countries, with about one-third of victims appearing to be government systems. PhantomCore is associated with custom malware families including PhantomRAT, PhantomRShell, PhantomTaskShell, PhantomProxyLite, PhantomStealer, Phantom Control Panel, PhantomSscp, PhantomRemote / PhantomeRemote / PhantomCore.PollDL, and PhantomeCore.GreqBackdoor v2. Reporting also describes use of third-party or legitimate tools including MeshAgent, MeshCentral, RSocx, Rclone, OpenSSH, UPX, XenArmor All-In-One Password Recovery Pro, Impacket SMBExec, and LockBit 3.0 in at least one intrusion. Observed initial access methods include spearphishing via compromised corporate email accounts, malicious ZIP/RAR/LNK attachments disguised as documents, phishing links leading to fake CAPTCHA pages that deliver MeshAgent, exploitation of WinRAR CVE-2023-38831, exploitation of TrueConf vulnerabilities BDU:2025-10114, BDU:2025-10115, and BDU:2025-10116, and compromises of Exchange login pages with keylogger code. The actor has used compromised legitimate websites and phishing domains to host payloads. Reported tradecraft includes PowerShell- and cmd-based execution; scheduled-task persistence using names such as Yandex Update, Microsoft Update, Update, SSH, SSHService, DNS, Yandex Task {user_sid}, and MicrosoftStatisticCore-related naming; creation of services and local accounts; web shell deployment on TrueConf servers; DLL hijacking via libEGL.dll; anti-analysis checks in PhantomRAT; obfuscated and Base64-encoded PowerShell; disabling Microsoft Defender; clearing event logs; masquerading malware as legitimate Windows files; and deletion of tools after operations. Post-compromise activity includes host and network discovery with native Windows commands, credential theft from LSASS and NTDS.dit, theft of browser authentication data from Chrome and Yandex via PhantomStealer and XenArmor, lateral movement via RDP, SMB, WinRM, and Impacket SMBExec, and command-and-control over HTTP, HTTPS, and SSH including SSH tunneling over port 443 and use of nonstandard ports such as 81, 8000, and 8080. Infrastructure described in the reporting includes phishing domains with fake CAPTCHAs, VPS servers mostly rented from Russian hosting providers, compromised legitimate servers, DynDNS services, impersonation of services such as Mattermost and Nextcloud, and Mega.nz accounts for exfiltration. The reporting also notes overlaps between PhantomCore and Bearlyfy, and one source explicitly refers to PhantomCore as "PhantomCore (Head Mare)."
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Where they're from
Attributed origin per open-source reporting.
- RU
Tradecraft
78 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
10 malware families attributed to this actor across reporting.
5 additional families tracked in Mallory.
Associated vulnerabilities
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
Observables
24 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Group aligned with Ukrainian interests that attacks Russian and Belarusian companies and conducts APT-style campaigns emphasizing reconnaissance, persistence, and data exfiltration.
Suspected pro-Ukrainian cluster targeting Russian companies across multiple sectors using phishing with ZIP attachments to deliver PowerShell-based malware similar to PhantomRemote.
Conducting phishing campaigns targeting Russian and Belarusian companies.
Фишинговые/вредоносные email-рассылки по российским и белорусским организациям с доставкой LNK, который запускает многостадийный PowerShell-загрузчик/бекдор. Закрепляется через планировщик задач и реализует polling C2 (получение команд и отправка результатов).
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.