PhantomNet, also known as SManager and DOWNTOWN, is a Windows backdoor associated primarily with Chinese espionage activity and has been linked in public reporting to clusters including TA428 and later China-nexus intrusion sets such as UNC5330 and activity overlapping REF5961 and Crimson Palace. It has appeared in targeted operations against government and regional organizations in Asia, including Vietnam, Mongolia, Japan, Hong Kong-related targets, Southeast Asian government entities, and Russian government victims, and has also been delivered through a software supply-chain compromise affecting Vietnamese government certificate software.
PhantomNet is part of a broader tooling lineage closely related to TManger and Albaniiutas. Reported variants exist in both SSL/TLS and raw TCP forms and share distinctive implementation traits such as exported service-oriented entry points, similar configuration structures, overlapping command handling, and plugin-loading logic. The malware is generally characterized as a simple but extensible backdoor: it collects host information, establishes command-and-control communications, and can install or execute additional malicious plugins or PE payloads supplied by the operator. Observed host profiling includes system and user context details such as computer and host names, network information, operating system version, language, username, browser information, and privilege level.
Operationally, PhantomNet supports encrypted C2 over HTTPS and has been noted for using certificate pinning, an uncommon feature among malware families, to resist interception and analysis. Some deployments retrieve proxy settings to ensure outbound connectivity in restricted enterprise environments. Public reporting also describes persistence via Windows services when elevated privileges are available and alternate user-level persistence mechanisms when they are not. In multiple campaigns, PhantomNet was launched through trojanized installers or setup-stage droppers that unpacked the backdoor and then executed it either as a service component or through exported DLL functions.
PhantomNet has been used as a post-compromise implant as well as an initial foothold delivered through trojanized software packages and malicious document chains. In one documented supply-chain intrusion, attackers modified legitimate government software installers so that victims manually downloading and executing the packages installed PhantomNet alongside the expected application. Other reporting ties PhantomNet to plugin deployment after compromise and to campaigns using malicious documents and staged downloaders.
The malware’s plugin architecture materially expands its utility beyond basic beaconing. Reported plugins and follow-on payload behavior indicate support for loading additional modules in memory, and at least one observed plugin was assessed as enabling credential theft and lateral movement through embedded credential-dumping functionality. PhantomNet has also been observed in broader intrusion ecosystems alongside other espionage implants and loaders, reinforcing its role as a reusable backdoor within long-term access operations rather than a standalone one-off tool.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Post-compromise activity by UNC5330 includes deployment of PHANTOMNET and TONERJAM.
Post-compromise activity by UNC5330 includes deployment of PHANTOMNET and TONERJAM.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BRONZE DUDLEY ... Tools ... NCCTrojan, PhantomNet, PoisonIvy, Royal Road
Post-compromise activity by UNC5330 includes deployment of PHANTOMNET and TONERJAM.
これらのファイルはPhantomNetというPDBを含んでいたことから、以下ではPhantomNetと呼びます。PhantomNetの挙動はTmangerやSmanagerと類似しています。
これらのファイルはPhantomNetというPDBを含んでいたことから、以下ではPhantomNetと呼びます。PhantomNetの挙動はTmangerやSmanagerと類似しています。
26 distinct techniques documented for this family, organized by ATT&CK tactic.
In December 2020, Ignacio Sanmillan and Matthieu Faou released an excellent report on a Vietnamese supply-chain attack that used PhantomNet ( aka SManager) malware.
UNC5330 has employed Windows Management Instrumentation (WMI) to perform reconnaissance, move laterally, manipulate registry entries, and establish persistence.
The researchers noted that the malware’s persistence was established via a scheduled task that called the malicious DLL’s export, ‘Entery’.
If the user doesn’t have admin privileges, PhantomNet persists via a scheduled task.
他にもRTFファイルを用いて脆弱性を悪用すること、CABファイルを用いること、サブコマンドを用いること、Export関数名などが類似しています。
ServiceMain takes a service name as an argument and attempts to register a service control handler with a specific HandlerProc function meant to check and set the status of that service. With a valid service status handle, Mail-O detaches the calling process from its console, changes the service status values to reflect its current running state, and calls the Entery function.
MDR launched the hunt after the discovery of a DLL sideloading technique that exploited VMNat.exe, a VMware component... The Crimson Palace campaign included over 15 distinct DLL sideloading scenarios... Cluster Alpha activity included multiple sideloading attempts to deploy various malware... Cluster Bravo used renamed versions of a signed side-loadable binary (mscorsvw.exe) to obfuscate backdoor deployment.
The researchers noted that the malware’s persistence was established via a scheduled task that called the malicious DLL’s export, ‘Entery’.
If the user doesn’t have admin privileges, PhantomNet persists via a scheduled task.
Use of renamed versions of a signed side-loadable binary (mscorsvw.exe) to obfuscate backdoor deployment and move laterally... Sophos observed the PhantomNet backdoor implant (sslwnd64.exe)...
the HUI loader (msedge_elf.dll), which de-obfuscated the file log.ini to reveal a Cobalt Strike reflective Loader
the actor frequently abused endpoint protection software binaries to sideload their malicious payloads.
MDR launched the hunt after the discovery of a DLL sideloading technique that exploited VMNat.exe, a VMware component... The Crimson Palace campaign included over 15 distinct DLL sideloading scenarios... Cluster Alpha activity included multiple sideloading attempts to deploy various malware... Cluster Bravo used renamed versions of a signed side-loadable binary (mscorsvw.exe) to obfuscate backdoor deployment.
Moreover, the adoption of SSL/TLS in malware is not restricted to the HTTPS protocol; other protocols, including SMTP and custom TCP protocols, were also found using SSL/TLS. | Over the last six years there has been an increased shift by malware authors to secure their C&C communications using the SSL/TLS protocol to stymie detection and blend in with normal traffic.
PhantomNet can retrieve the proxy configuration of the default browser and use it to connect to the C&C server.
the actor created a SOCKS proxy to be used by the Microsoft Distributed Transaction Coordinator (MSDTC) service
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A simple backdoor used to establish C2 communications, collect victim information, and load additional plugins or payloads.
A backdoor used as a persistent C2 implant in the campaign.
Listed as a tool used by the BRONZE DUDLEY threat profile.
Espionage toolset component used in campaigns attributed to Worok/shared tooling ecosystems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.