PhantomGraph is a modular Windows backdoor associated with the Head Mare threat group. It uses Microsoft OneDrive for command-and-control, receiving attacker instructions and returning execution results through an attacker-controlled account. Its architecture separates communication and command execution into two DLL modules: one retrieves commands and transmits results, while the other parses and executes instructions and stores their output. Commands are executed through the Windows command interpreter and temporary batch files. Both components are installed as Windows services for persistence. The use of a legitimate cloud-storage service allows malicious communications to blend with ordinary cloud traffic. PhantomGraph also shares partial code overlap with PhantomCore.
PhantomGraph has been deployed through web shells on compromised Windows TrueConf servers after attackers exploited server vulnerabilities to obtain privileged code execution. It provided an additional command-and-control channel alongside web-shell access. Operators have used it for system and user reconnaissance, LSASS memory dumping to obtain credentials, and reverse SSH tunneling. Its deployment has been observed in Head Mare campaigns targeting Russian organizations across instrumentation, electronics, transportation, energy, IT, and software development.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
C помощью веб‑шелла помимо PhantomCore злоумышленники загружают бэкдор, который мы назвали PhantomGraph, состоящий из двух модулей.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
the attackers exploited a chain of vulnerabilities in the TrueConf video conferencing server... The attackers connect to the TrueConf server without prior authorization via port 4307/TCP... attackers call a server function to transmit a malicious script and execute it on the server.
The attackers distribute their backdoors using various methods, including phishing, exploiting public web servers, or through a subcontractor.
[The vulnerabilities] allowed the attackers to run a malicious script ... and execute commands on the underlying operating system.
Head Mare, now assessed as an APT group, exploited two vulnerabilities in unpatched TrueConf video conferencing servers to achieve SYSTEM-level code execution and deploy a web shell.
/etc/systemd/system/omicluster.service /etc/systemd/system/schedul2-bin.service
Both components establish persistence on the server by creating services with the names SysExcSvc and SysReadSvc.
To escape the isolated environment, attackers exploit a second vulnerability... Exploiting this vulnerability allows them to bypass the restrictions of the isolated environment and proceed to execute commands in the context of the operating system... with the privileges of the NT AUTHORITY\SYSTEM account.
/etc/systemd/system/omicluster.service /etc/systemd/system/schedul2-bin.service
Both components establish persistence on the server by creating services with the names SysExcSvc and SysReadSvc.
The attackers used an account on Microsoft OneDrive cloud storage as their command-and-control (C2) server.
Exfiltration and C2 communications were conducted over both custom malicious domains and IP addresses, as well as via OneDrive cloud storage.
The attackers use a Microsoft OneDrive cloud storage account as the command and control (C&C) server... on *nix systems, the attackers install a backdoor that uses GitHub as a command and control channel.
PhantomGraph ... is capable of receiving commands through a Microsoft OneDrive account, executing these commands and returning the results.
41 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A two-DLL backdoor that uses a Microsoft OneDrive account for command-and-control, executes received commands, returns results, supports LSASS memory dumping for credential theft, reconnaissance, and reverse SSH tunneling.
Named in the indicators/detection section as Trojan.Win64.PhantomGraph, with an MD5 hash provided, but not otherwise described in the content.
A malware payload delivered in the TrueConf server intrusion campaign attributed to Head Mare.
A backdoor used on compromised TrueConf servers as a backup command-and-control channel, consisting of communication and execution modules that use Microsoft OneDrive for C2 and persist via the SysExcSvc and SysReadSvc services.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.