Phantom is a malware name used for multiple unrelated threats, but the strongest malware-specific evidence here supports Phantom as a Windows information stealer. It has been observed delivered by fake Adobe update or installer lures and is associated with social-engineering-driven infection chains. Reported behavior includes theft of sensitive user data and exfiltration of stolen information over SMTP. Phantom has also been referenced alongside other commodity stealers in criminal distribution ecosystems and has been used as a payload delivered by other malware loaders. Separately, the name Phantom has also been used in public reporting for an NSO Group phone-hacking product described as functionally aligned with Pegasus and marketed to U.S. government customers, but that usage refers to a mercenary spyware platform rather than the commodity infostealer activity most directly supported for this malware entry. Because the same name is applied to distinct tools, attribution, platforming, and capability claims beyond the stealer activity should be treated cautiously unless further disambiguated.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Fortinet Secure Sockets Layer (SSL) VPN is vulnerable to unauthenticated directory traversal... Multiple malware campaigns have taken advantage of this vulnerability. The most notable being Cring ransomware (also known as Crypt3, Ghost, Phantom, and Vjszy1lo).
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
That spyware system, dubbed “Phantom,” was offered secretly to U.S. government agencies by the NSO Group... During a presentation to officials in Washington, the company demonstrated a new system, called Phantom, that could hack any number in the United States that the F.B.I. decided to target.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
...uses reflective loading techniques to inject and run a DLL inside the memory space of the w3wp.exe worker pool process. | Phantom is project created to perform loading and executing .NET assemblies directly in memory within an IIS environment running in full-trust mode.
"Standalone apps on Google Play... embed modules like Nova clicker"; "Google removed these after notification"
...uses reflective loading techniques to inject and run a DLL inside the memory space of the w3wp.exe worker pool process. | Phantom is project created to perform loading and executing .NET assemblies directly in memory within an IIS environment running in full-trust mode.
Phantom is project created to perform loading and executing .NET assemblies directly in memory within an IIS environment running in full‑trust mode. Instead of relying on file‑based approach, it uses reflective loading techniques to inject and run a DLL inside the memory space of the w3wp.exe worker pool process
Israel-based NSO Group develops Pegasus, a spyware that allows its government customers near-unfettered access to a victim’s device, including their personal data and their location.
Pegasus is a so-called zero-click hacking tool that can invade a target’s mobile phone and extract messages, photos, contacts, messages and video recordings.
Pegasus is a so-called zero-click hacking tool that can invade a target’s mobile phone and extract messages, photos, contacts, messages and video recordings.
Israel-based NSO Group develops Pegasus, a spyware that allows its government customers near-unfettered access to a victim’s device, including their personal data and their location.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Outil/malware connexe mentionné aux côtés de Pegasus dans la section récapitulative des malwares/outils, sans détail supplémentaire dans le contenu.
Named as one of 17 Android malware families detected in the wild over four months.
Android click-fraud trojan family using TensorFlow.js to detect/interact with ad elements in a hidden WebView; includes a WebRTC-based mode to stream the virtual browser screen to attackers for interactive control; distributed via mobile games in Xiaomi GetApps and other third-party stores.
Phantom is an information stealer malware delivered by loaders such as BlackHawk, used to exfiltrate sensitive data from infected systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.