Phoreal is an unvalidated threat-actor label appearing in connection with a Windows intrusion involving malicious document execution, PowerShell-based payload retrieval, unsigned loader execution, host and domain discovery, persistence via autorun configuration, additional payload download, and attempted lateral movement using remote service interaction and WMI. Observed behavior includes user-execution-driven initial access, ingress tool transfer, command execution for system and network reconnaissance, use of rundll32 to load an unsigned module, and follow-on communications consistent with web-based command-and-control or possible exfiltration. The activity also demonstrated persistence and post-compromise expansion attempts against another internal host. Attribution for this label is not established at high confidence. Although the surrounding context includes references to other names sometimes associated with advanced intrusion activity, there is no reliable evidence tying Phoreal to a specific known cluster, nation-state program, or intrusion set. Available information supports only the operational behaviors observed in the intrusion, not a corroborated actor identity, origin, or broader campaign history.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.