PhantomNet, also known as SManager and DOWNTOWN, is a modular Windows backdoor used in cyberespionage operations. It collects victim-system information and downloads and executes additional payloads through a plugin architecture. Collected information includes computer and host names, operating-system version, language settings, username, default browser, network addressing, and administrative privilege status. Its command set supports plugin management and cleanup, allowing operators to extend its functionality after deployment.
PhantomNet exists in TCP and SSL/TLS variants. Observed HTTPS variants use Microsoft Security Support Provider Interface functions and certificate pinning to protect command-and-control communications against interception. The backdoor can retrieve system proxy settings to reach its command-and-control infrastructure, and observed samples encrypt their configuration with RC4. Deployment components establish persistence through Windows services when administrative privileges are available or scheduled tasks when they are not.
PhantomNet was distributed in a 2020 software supply-chain compromise of the Vietnam Government Certification Authority, in which legitimate digital-signature software installers were modified to deploy the backdoor alongside the genuine application. Victims were also observed in the Philippines. The malware is associated with the China-linked espionage actor TA428, also tracked as BRONZE DUDLEY, and has been used by Worok and other China-nexus activity clusters. UNC5330 deployed it during post-compromise activity following exploitation of Ivanti Connect Secure vulnerabilities. It was also deployed by Cluster Alpha during the Crimson Palace espionage campaign against a Southeast Asian government organization.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Mandiant's previous blog post, Cutting Edge, Part 3: Investigating Ivanti Connect Secure VPN Exploitation and Persistence Attempts, details zero-day exploitation of CVE-2024-21893 and CVE-2024-21887 by a suspected China-nexus espionage actor that Mandiant tracks as UNC5325.
UNC5330 has been observed chaining CVE-2024-21893 and CVE-2024-21887 to compromise Ivanti Connect Secure VPN appliances as early as Feb. 2024. Post-compromise activity by UNC5330 includes deployment of PHANTOMNET and TONERJAM.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Post-compromise activity by UNC5330 includes deployment of PHANTOMNET and TONERJAM.
BRONZE DUDLEY ... Tools ... NCCTrojan, PhantomNet, PoisonIvy, Royal Road
これらのファイルはPhantomNetというPDBを含んでいたことから、以下ではPhantomNetと呼びます。PhantomNetの挙動はTmangerやSmanagerと類似しています。
これらのファイルはPhantomNetというPDBを含んでいたことから、以下ではPhantomNetと呼びます。PhantomNetの挙動はTmangerやSmanagerと類似しています。
26 distinct techniques documented for this family, organized by ATT&CK tactic.
In December 2020, Ignacio Sanmillan and Matthieu Faou released an excellent report on a Vietnamese supply-chain attack that used PhantomNet ( aka SManager) malware.
UNC5330 has employed Windows Management Instrumentation (WMI) to perform reconnaissance, move laterally, manipulate registry entries, and establish persistence.
The researchers noted that the malware’s persistence was established via a scheduled task that called the malicious DLL’s export, ‘Entery’.
If the user doesn’t have admin privileges, PhantomNet persists via a scheduled task.
他にもRTFファイルを用いて脆弱性を悪用すること、CABファイルを用いること、サブコマンドを用いること、Export関数名などが類似しています。
ServiceMain takes a service name as an argument and attempts to register a service control handler with a specific HandlerProc function meant to check and set the status of that service. With a valid service status handle, Mail-O detaches the calling process from its console, changes the service status values to reflect its current running state, and calls the Entery function.
MDR launched the hunt after the discovery of a DLL sideloading technique that exploited VMNat.exe, a VMware component... The Crimson Palace campaign included over 15 distinct DLL sideloading scenarios... Cluster Alpha activity included multiple sideloading attempts to deploy various malware... Cluster Bravo used renamed versions of a signed side-loadable binary (mscorsvw.exe) to obfuscate backdoor deployment.
The researchers noted that the malware’s persistence was established via a scheduled task that called the malicious DLL’s export, ‘Entery’.
If the user doesn’t have admin privileges, PhantomNet persists via a scheduled task.
Use of renamed versions of a signed side-loadable binary (mscorsvw.exe) to obfuscate backdoor deployment and move laterally... Sophos observed the PhantomNet backdoor implant (sslwnd64.exe)...
the HUI loader (msedge_elf.dll), which de-obfuscated the file log.ini to reveal a Cobalt Strike reflective Loader
the actor frequently abused endpoint protection software binaries to sideload their malicious payloads.
MDR launched the hunt after the discovery of a DLL sideloading technique that exploited VMNat.exe, a VMware component... The Crimson Palace campaign included over 15 distinct DLL sideloading scenarios... Cluster Alpha activity included multiple sideloading attempts to deploy various malware... Cluster Bravo used renamed versions of a signed side-loadable binary (mscorsvw.exe) to obfuscate backdoor deployment.
Moreover, the adoption of SSL/TLS in malware is not restricted to the HTTPS protocol; other protocols, including SMTP and custom TCP protocols, were also found using SSL/TLS. | Over the last six years there has been an increased shift by malware authors to secure their C&C communications using the SSL/TLS protocol to stymie detection and blend in with normal traffic.
PhantomNet can retrieve the proxy configuration of the default browser and use it to connect to the C&C server.
the actor created a SOCKS proxy to be used by the Microsoft Distributed Transaction Coordinator (MSDTC) service
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A simple backdoor used to establish C2 communications, collect victim information, and load additional plugins or payloads.
A backdoor used as a persistent C2 implant in the campaign.
Listed as a tool used by the BRONZE DUDLEY threat profile.
Espionage toolset component used in campaigns attributed to Worok/shared tooling ecosystems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.