Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
PhantomCore снова использует уязвимость CVE-2023-38831, эксплуатация которой приводит при открытии PDF файла к запуску исполняемого файла, содержащегося в одноименной директории архива. | «Разработали PhantomDL 3 версии (v.3), а затем выпустили еще одну версию (v.4), которую частично дополнили возможностями PhantomRAT».
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
«Разработали PhantomDL 3 версии (v.3), а затем выпустили еще одну версию (v.4), которую частично дополнили возможностями PhantomRAT».
Head Mare, which first emerged in 2023 on the social platform X, is known for using its own custom malware, including PhantomDL and PhantomCore, and for exploiting newly disclosed vulnerabilities in phishing campaigns.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Head Mare, which first emerged in 2023 on the social platform X, is known for using its own custom malware, including PhantomDL and PhantomCore, and for exploiting newly disclosed vulnerabilities in phishing campaigns.
Промежуточный скрипт написан на PowerShell. Он скачивает с удаленного сервера файл USOCachedData.txt... обеспечивает закрепление в системе и автозапуск.
Произвольная команда используется для выполнения команд в интерпретаторе Windows (cmd.exe)
XLS-файл содержит обфусцированный VBA, задачей которого является загрузка шеллкода по ссылке и его запуск в контексте собственного процесса.
PhantomCore используют загрузчик PhantomDL v.3, который взаимодействует с управляющим сервером через HTTP-протокол.
PhantomCore используют загрузчик PhantomDL, который взаимодействует с управляющим сервером через HTTP-протокол.
по команде «install» получают от управляющего сервера URL-адрес для загрузки следующей стадии
54 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom malware used by Head Mare in its operations, likely serving as a downloader component based on its name and context.
Go-based downloader first detected in March 2024 and attributed by F6 to PhantomCore with high confidence. Delivered through password-protected RAR archives exploiting CVE-2023-38831 in WinRAR versions below 6.23; phishing is suspected but the initial delivery vector was not established. Collects the victim's computer/domain name and sends it with a generated UUID to an HTTP command-and-control server. Its infrastructure rejects connections from non-Russian IP addresses. The 'install' command retrieves a payload URL, downloads the next stage into %APPDATA%\Microsoft\Windows, executes it, and reports completion; 'bay' terminates execution. Early samples were apparently obfuscated with garble. Lure documents suggest targeting Russian defense-related organizations and include a nuclear-sector enterprise.
PhantomCore’s loader, used in repeated phishing campaigns against Russian organizations. The analyzed Go versions use suspected Garble obfuscation; one version 4 sample was also packed with UPX. Version 3, identified on June 7, 2024, downloads and launches additional payloads, executes shell commands, changes its working directory, and reports command results over HTTP. Version 4 samples appeared in archives discovered on July 4 and incorporate some PhantomRAT functionality. Delivery includes malicious RAR archives exploiting WinRAR CVE-2023-38831 and an alternative XLS/VBA chain that downloads and executes PhantomDL shellcode in memory. Some attempts failed because of incorrectly constructed exploit archives or a mismatch between downloaded executable payloads and shellcode execution logic. Researchers also identified a later modified loader rewritten in C++.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.