TetrisPhantom is a sophisticated cyber-espionage threat actor identified in late 2024 and associated with targeted intrusions against government systems in the Asia-Pacific region. The actor is notable for compromising secure USB drives used to transfer encrypted data, including into air-gapped environments, by trojanizing the legitimate access software bundled with those devices. This tradecraft enables propagation across isolated networks and staged exfiltration when infected media are later connected to internet-accessible systems. The actor’s malware ecosystem includes trojanized USB access software and supporting components such as AcroShell and XMKR. AcroShell functions as an initial payload and backdoor capable of communicating with command-and-control infrastructure, retrieving additional payloads, and stealing documents and other sensitive files. XMKR is used on Windows systems to compromise connected secure USB devices, replicate the intrusion chain to additional hosts, and write stolen data back to removable media for later exfiltration. Reported techniques include low-level communication with USB devices via direct SCSI commands, code injection into legitimate software, self-replication through connected secure USB drives, and virtualization-based obfuscation to hinder analysis and detection. Observed victimology indicates a highly selective operation with a small number of infections in government networks, consistent with long-term intelligence collection rather than broad criminal activity. Espionage is the actor’s consistent objective. TetrisPhantom has also been discussed as a possible link to the later GoSerpent espionage campaign targeting government and diplomatic entities in Southeast Asia, based on overlaps in victims, tooling, and operational methodology; however, that attribution remains unconfirmed and should be treated cautiously. TetrisPhantom is currently an unattributed or emerging threat actor rather than a confirmed nation-state designation, although its operational sophistication, patience, and targeting profile are consistent with a well-resourced espionage operator.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
25 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
22 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Possibly linked to the GoSerpent espionage campaign based on shared victims, tooling, and methods, but not confirmed as the operator.
Potentially linked to a sophisticated espionage-oriented campaign targeting government and diplomatic entities in Southeast Asia using GoSerpent, Stowaway, ThumbcacheService, credential dumping tools, and TmcLoader/TmcPayload for long-term collection and exfiltration of sensitive data.
Potentially linked to the GoSerpent espionage campaign targeting government and diplomatic entities in Southeast Asia, involving long-term access, credential dumping, file collection, proxying, and staged data exfiltration.
Espionage-focused campaign targeting government networks in the Asia-Pacific region using trojanized secure USB drive software to compromise connected systems, propagate into air-gapped environments, steal files, and exfiltrate data via internet-connected infected hosts.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.