Phantom Bot
Phantom Bot is a Go-based DDoS botnet payload delivered via the malicious npm package axois-utils in a broader npm supply-chain/typosquatting campaign attributed to the same publisher that distributed multiple malicious packages. The malware is explicitly referred to in the package as a “phantom bot.” Its documented capabilities include flooding targets using HTTP, TCP, UDP, and reset requests, turning infected systems into DDoS nodes. Reported persistence mechanisms allow it to remain on infected machines even after the npm package is deleted; supporting reporting states this persistence is achieved on Windows by adding the payload to the Windows Startup folder and on Linux by creating a scheduled task. The campaign was identified by OX Security and involved packages published by the npm user deadcode09284814 alongside other stealer payloads. High-confidence context indicates the overall campaign targeted npm users and was assessed as financially motivated, while the DDoS capability also raised the possibility of disruptive or DDoS-for-hire use. No Phantom Bot-specific C2 or unique IOC beyond delivery through axois-utils is directly provided in the content.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Techniques & procedures
8 distinct techniques documented for this family, organized by ATT&CK tactic.
Resource Development
1 technique
Resource Development
Initial Access
1 technique
Initial Access
Execution
1 technique
Execution
Persistence
2 techniques
Persistence
Privilege Escalation
2 techniques
Privilege Escalation
Command and Control
1 technique
Command and Control
Exfiltration
1 technique
Exfiltration
IOCs tracked for this family
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Go-based bot payload delivered via a malicious npm package that establishes persistence and turns infected systems into a DDoS botnet capable of HTTP, TCP, UDP, and reset-request flooding.
Golang-based DDoS botnet capable of flooding targets over HTTP, TCP, and UDP. It also establishes persistence on Windows and Linux systems.
Go-based DDoS botnet payload delivered via a malicious npm package. It floods targets with HTTP, TCP, UDP, and Reset requests and uses persistence to remain on infected machines after package deletion.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.