PhantomRAT is a Windows remote-access trojan developed and deployed by the PhantomCore cyberespionage group in campaigns against Russian organizations since at least January 2024. Targeted sectors include manufacturing, information technology, leasing, technology parks, and oil and gas. Originally implemented in C# using .NET, PhantomRAT was rewritten in Go by May 2024, with subsequent versions expanding its command set and support for separately deployed modules.
PhantomRAT supports bidirectional file transfer, file exfiltration, downloading and launching additional payloads, and Windows command-shell execution with output returned to its command-and-control server. It collects host and user identifiers, local and external network addresses, and operating-system information. The .NET implementation communicates through RSocket over TCP, supports primary and secondary command-and-control endpoints, and encrypts command-session exchanges using AES-256-CBC. Observed variants employ packing or obfuscation, and anti-analysis checks include VMware detection and debugger detection.
Delivery uses targeted phishing emails, including messages sent from compromised corporate accounts, with business-document lures inside password-protected RAR archives. Infection chains exploit CVE-2023-38831 in WinRAR versions earlier than 6.23, causing a malicious executable to run when the recipient attempts to open an apparently legitimate PDF. An associated downloader retrieves PhantomRAT and establishes persistence through a disguised Windows scheduled task. Later PhantomRAT versions support installing and executing auxiliary modules, including a persistence component that creates scheduled tasks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
PhantomCore exploits a variation of CVE-2023-38831 using RAR archives instead of ZIP archives. In WinRAR versions earlier than 6.23, attempting to open the enclosed PDF launches a malicious executable from a same-named directory.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
«Злоумышленники успели переписать свой троян удаленного доступа PhantomRAT с языка программирования C# на Go, обогатив его дополнительными командами».
25 distinct techniques documented for this family, organized by ATT&CK tactic.
PhantomCore используют, предположительно, утилиту garble для обфускации вредоносных программ.
PhantomCore uses UPX (the Ultimate Packer for Executables) to pack PhantomRAT, PhantomRShell, and lure documents disguised as archives
«PhantomCore используют вредоносное ПО PhantomRAT, которое расшифровывает полученные команды от сервера перед их выполнением.»
Действие запланированной задачи имеет следующий шаблон: pcalua.exe -a {filepath}.
«Версия ОС, внешний и внутренний IP-адреса, имя хоста и имя пользователя.»
«PhantomRAT использует RSocket-протокол для сетевого взаимодействия.»
«PhantomCore.Downloader ... загружает следующую стадию с filetransfer[.]io используя HTTP-протокол.»
PhantomCore используют PhantomRAT, который по команде socks5 (start | stop) {arg} выполняет запуск/остановку socks5-proxy.
по команде «install» получают от управляющего сервера URL-адрес для загрузки следующей стадии
PhantomCore используют вредоносное ПО PhantomRAT, которое имеет возможность загрузки файлов на зараженную систему с помощью команды «upload».
PhantomCore uses MeshAgent along with its in-house RAT utilities PhantomRAT and PhantomRShell
32 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan used by PhantomCore and delivered by PhantomCore.Downloader in the group's first known January 2024 attack. Shared project-path naming, class and method names, and similar command-and-control configuration variable names provide supporting evidence for attributing PhantomDL to the same group. The reference does not establish that PhantomDL delivered PhantomRAT.
Previously undescribed .NET remote access trojan used by PhantomCore against Russian companies. Delivered by PhantomCore.Downloader in a phishing chain exploiting CVE-2023-38831 through RAR archives. Packaged as a single-file .NET application, it collects host and operating-system information, transfers files, exfiltrates data, and executes commands through cmd.exe. It communicates using RSocket over TCP and encrypts command traffic with AES-256-CBC using a zero-filled initialization vector. Its configuration supports primary and fallback C2 endpoints. The report identifies EventManager.exe, AppManager.exe, and WinDidget.exe as operational samples and Test2.exe as an apparent test sample.
PhantomCore’s remote-access trojan, originally written in C# and subsequently rewritten in Go with suspected Garble obfuscation. Version 2 was identified on May 8, 2024, and version 3 on May 15. It executes Windows shell commands, transfers files to and from infected systems, exfiltrates files through C2, and downloads additional modules. Version 3 adds management of a SOCKS5 proxy and a persistence helper that creates scheduled tasks triggered by user logon or system boot. A further module named syscall.exe is referenced, but researchers did not obtain it or establish its functionality.
PhantomRAT is a custom remote access trojan used by PhantomCore for phishing-based initial access, command execution, anti-debugging, sandbox evasion, and ongoing remote control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.