PhantomRemote is a custom Windows backdoor associated with the Head Mare intrusion set, also tracked as Rainbow Hyena. It has been used in targeted phishing operations against Russian organizations, including entities in healthcare, information technology, aerospace, aviation, electronic warfare, and related defense-support sectors. Reported campaigns in 2025 delivered PhantomRemote through weaponized archive attachments containing shortcut files that invoked PowerShell to extract and launch a malicious DLL alongside a decoy document, indicating a social-engineering-driven initial access chain centered on spearphishing.
Operationally, PhantomRemote functions as a remote-access backdoor that provides attackers with post-compromise control over infected systems. Observed delivery chains show it being deployed as a DLL payload and communicating with command-and-control infrastructure over HTTP using standard request methods, consistent with interactive remote tasking and follow-on intrusion activity. Its use by Head Mare aligns with broader tradecraft involving compromised email infrastructure, deceptive lures, and malware delivery against strategically significant Russian targets.
PhantomRemote appears to be a bespoke malware family rather than a commodity tool, and its documented use is closely tied to campaigns attributed to Head Mare/Rainbow Hyena. The malware has been observed in operations aimed at organizations connected to aviation operations, aircraft systems, electronic warfare production, and other sectors of geopolitical interest, suggesting an espionage- or disruption-oriented role within targeted intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
As previous campaigns, the DLL happens to be a PhantomRemote payload, a custom malware made by the Head Mare intrusion set.
As previous campaigns, the DLL happens to be a PhantomRemote payload, a custom malware made by the Head Mare intrusion set.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
Once launched, the LNK executes PowerShell commands... The BATCH script would launch PowerShell commands to download an actual PowerShell script file named “dis.ps1”.
Once launched, the LNK executes PowerShell commands that search for an array of bytes located at the end of the ZIP file... The next PowerShell command then look for a second array of bytes also located at the end of the ZIP file
According to IBM’s X-Force, the malware collects system information and generates a beacon that will transmit the following information to the C2... An initial HTTP POST request is sent to the server's '/register' endpoint, transmitting the gathered system information.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a similar PowerShell-based malware family; used as a comparison point for a phishing-delivered PowerShell payload.
Custom backdoor used by Head Mare/Rainbow Hyena, deployed via LNK and DLL stages using COM object hijacking; it gathers initial system information and communicates with C2 over HTTP GET and POST requests.
PhantomRemote is a custom C++ backdoor used for system information collection, loading additional executables, and executing commands via cmd.exe, distributed via phishing emails.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.