PhantomCore is a suspected pro-Ukrainian intrusion set active since at least 2022 and primarily known for targeting Russian and Belarusian organizations. The group has been associated with cyber-espionage operations focused on data theft and remote access, and later reporting indicates a shift in some operations toward disruptive and ransomware-style activity. PhantomCore has been linked to attacks against government entities and a broad range of commercial sectors, including finance, utilities and municipal services, aerospace, chemicals, construction, consumer-facing services, manufacturing, e-commerce, and other Russian enterprises. Some reporting also ties the group to compromises of Microsoft Exchange servers across multiple countries through credential-harvesting code injected into login pages. PhantomCore relies heavily on phishing and exploitation for initial access. Observed delivery methods include spearphishing emails sent from compromised corporate mailboxes, malicious attachments such as shortcut files disguised as documents, phishing links leading to fake CAPTCHA pages, and exploitation of public-facing software vulnerabilities including CVE-2023-38831 and multiple TrueConf flaws. The actor has also conducted active scanning of exposed web resources and deployed web shells on compromised servers. The group develops and operates a substantial custom malware ecosystem. Reported tooling includes PhantomRAT, PhantomRShell, PhantomTaskShell, PhantomProxyLite, PhantomStealer, PhantomSscp, PhantomRemote or PollDL-like PowerShell backdoors, and a Phantom control panel. PhantomCore also uses legitimate or dual-use tools such as MeshAgent, Rclone, OpenSSH, XenArmor, RSocx, and Impacket. Its malware and scripts support remote command execution, host profiling, credential access, browser data theft, file collection, tunneling, and operator tasking through HTTP, HTTPS, and SSH-based command-and-control. Persistence and post-compromise tradecraft include scheduled tasks disguised as legitimate software updates, malicious services, local account creation, abuse of valid accounts, and DLL hijacking or sideloading in TrueConf-related intrusions. Defense evasion has included obfuscated and Base64-encoded PowerShell, hidden execution, packed payloads, masquerading as legitimate Windows components, anti-analysis checks, deletion of tooling after use, disabling Microsoft Defender, and clearing event logs. Credential access has included theft of browser-stored authentication data, LSASS dumping, and acquisition of Active Directory credential material. Lateral movement has been observed via RDP, SMB, WinRM, and remote execution tooling, with some incidents using enterprise administration infrastructure to distribute ransomware. PhantomCore uses segmented infrastructure that includes phishing domains, rented VPS systems, compromised legitimate servers, SSH tunnels, and cloud storage for exfiltration. Infrastructure masking has included impersonation of legitimate services and use of dynamic DNS. Data theft is a recurring objective, with exfiltration performed through custom stealers, archive-and-transfer tooling, HTTP-based transfers, and cloud storage services. Although PhantomCore is chiefly documented as an espionage-oriented actor aligned with Ukrainian interests, some operations have reportedly evolved into ransomware or destructive activity. Reporting links the group to use of LockBit 3.0 in at least one intrusion and to later ransomware-related activity in the broader PhantomCore ecosystem. High-confidence characterization remains that PhantomCore is a Ukraine-linked actor focused primarily on Russian and Belarusian targets, combining phishing, exploitation, credential theft, lateral movement, and exfiltration with an increasingly disruptive operational profile.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
78 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 malware families attributed to this actor across reporting.
5 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
24 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Group aligned with Ukrainian interests that attacks Russian and Belarusian companies and conducts APT-style campaigns emphasizing reconnaissance, persistence, and data exfiltration.
Suspected pro-Ukrainian cluster targeting Russian companies across multiple sectors using phishing with ZIP attachments to deliver PowerShell-based malware similar to PhantomRemote.
Conducting phishing campaigns targeting Russian and Belarusian companies.
Фишинговые/вредоносные email-рассылки по российским и белорусским организациям с доставкой LNK, который запускает многостадийный PowerShell-загрузчик/бекдор. Закрепляется через планировщик задач и реализует polling C2 (получение команд и отправка результатов).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.