Ph4nt0m Security Team was a Chinese hacker group active during the 2000s and associated with the broader Chinese “red hacker” ecosystem. Like other prominent communities from that period, it appears to have combined a relatively small operational core with a much larger surrounding forum-style user base. Archived reporting indicates the group maintained roughly 11 to 20 core members between 2004 and 2009, while its broader community reached approximately 6,900 registered users at peak in 2006. This structure is consistent with contemporaneous Chinese hacker groups in which technically capable members conducted operations and maintained the organization, while many additional registrants primarily participated in discussion forums with limited vetting and uneven technical skill. Ph4nt0m Security Team should therefore be understood as a community-centered hacking group whose practical capability likely depended on a comparatively small cadre of core participants rather than its total registered membership. High-confidence information about specific campaigns, victim sectors, or distinct operational tradecraft beyond its role in the Chinese red-hacker milieu is currently not available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.