Ph4nt0m Security Team was a Chinese hacker group active in the 2000s and associated with the broader Chinese “red hacker” ecosystem. The group appears to have operated as a community with a relatively small core of technically active members supported by a much larger pool of forum registrants and peripheral participants. Reported historical figures place its core membership at roughly 11 to 20 members between 2004 and 2009, with several thousand registered users at peak scale. Ph4nt0m is notable as one of the better-known Chinese security teams of its era and as part of the informal talent networks that helped shape China’s early offensive cyber milieu. Membership in the group included individuals active in Chinese hacking circles, including the hacker known as envymask, also referred to as EMM. Reporting links envymask to RealSOI Computer Network Technology Company in Jinan and to work on an MS08-067 exploit adapted for Chinese-language Windows environments, indicating that at least some Ph4nt0m-associated personnel possessed exploit development or exploit adaptation capability. Available information supports characterizing Ph4nt0m primarily as a hacker collective and technical community rather than a ransomware or extortion actor. The group’s known profile centers on offensive security expertise, exploit-related activity, and participation in Chinese underground or nationalist hacker circles. High-confidence evidence in the supplied material does not establish specific victim countries, named sector targeting, or a clearly documented campaign set attributable directly to Ph4nt0m as an organization. It is, however, part of the historical ecosystem from which more formalized Chinese cyber talent and state-linked relationships are alleged to have emerged.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Chinese hacker/security team with a small core membership and a larger registered user base, consistent with the report’s described community structure (core operators vs. forum users).
Mentioned as the hacking group that envymask belonged to.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.