Phantom Mantis, previously known as ArmCorp and later associated with the partnership program The Gentlemen, is a ransomware-focused intrusion actor active since at least March 2025. The group is linked in reporting to operator LARVA-368 and has been observed evaluating or working with multiple ransomware brands before establishing its own ransomware-as-a-service operation. Its tradecraft is notable for a maintained portfolio of kernel-assisted tooling used to neutralize endpoint security, monitoring, and remote-management software immediately before ransomware deployment. A defining characteristic of Phantom Mantis is its use of pre-encryption security-disabling utilities, including the internally developed G12 and G13 tool line and an externally sourced bring-your-own-vulnerable-driver capability referred to as DriverKiller. G12 and G13 load kernel drivers, enumerate a fixed set of targeted security-related processes, and terminate matched processes through driver-mediated IOCTL requests. G13 substantially expands on G12 by adding driver-load inspection and blocking, destructive process-memory wiping, minifilter control, kernel-memory modification, staged transfer into target processes, and protected logging. The actor has also used a vulnerable legitimate third-party driver associated with CVE-2017-17472 to terminate operator-selected processes, indicating practical BYOVD adoption alongside bespoke tooling. Phantom Mantis demonstrates strong defense-evasion and post-compromise engineering capability. Observed behaviors include disabling antivirus and EDR products, interfering with monitoring and remote-management agents, loading kernel services, blocking defensive drivers from initializing, modifying kernel memory, and destroying user-space process memory. The group’s tooling also supports process termination, process targeting by name, and other low-level actions consistent with preparing victim environments for ransomware execution. Available evidence supports characterization of Phantom Mantis as a financially motivated ransomware actor with mature pre-deployment tooling rather than a purely opportunistic affiliate relying only on commodity utilities.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
It embeds a TG Soft VirIT Agent driver that exposes the interface documented in CVE-2017-17472, installs the driver as service DriverKiller, opens \\.\Viragtlt, and sends an operator-supplied process image name through IOCTL 0x82730030.
The group actively tracks and evaluates modern vulnerabilities, including CVE-2024-55591, CVE-2025-32433, and CVE-2025-33073, and combines them with technique-driven paths like backup and management-controller abuse and NTLM relay workflows, giving them a flexible exploitation pipeline.
The group actively tracks and evaluates modern vulnerabilities, including CVE-2024-55591, CVE-2025-32433, and CVE-2025-33073, and combines them with technique-driven paths like backup and management-controller abuse and NTLM relay workflows, giving them a flexible exploitation pipeline.
The group actively tracks and evaluates modern vulnerabilities, including CVE-2024-55591, CVE-2025-32433, and CVE-2025-33073, and combines them with technique-driven paths like backup and management-controller abuse and NTLM relay workflows, giving them a flexible exploitation pipeline.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operates a ransomware partnership program and provides affiliates with ransomware, target access, technical support, and kernel-assisted tools to disable security products prior to ransomware deployment.
Phantom Mantis is a cybercrime group that tested various ransomware strains before developing The Gentlemen RaaS.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.