Skip to main content
Mallory
MalwareUsed by 1 actorExploits 1 CVE

Phantom

Phantom is an overloaded malware/spyware name used in multiple distinct contexts in the provided content. High-confidence reporting identifies one Phantom as an NSO Group mobile spyware product marketed to U.S. government agencies under the Westbridge brand and described as effectively the U.S. version of Pegasus, with the two tools otherwise identical. It was reportedly demonstrated to U.S. officials, designed to hack U.S. phone numbers under a special Israeli license, and considered by the FBI and other U.S. agencies including the CIA, DEA, U.S. Secret Service, and U.S. Africa Command. The content also identifies Phantom as an information stealer seen in criminal malware campaigns. This Phantom infostealer has been distributed via fake Adobe installers and disguised Adobe updates; a reported Phantom v3.5 variant uses SMTP to exfiltrate stolen data. Additional reporting states Phantom has been delivered by a malware loader, was tracked alongside Stealerium by Proofpoint, and was used in campaigns involving social engineering around software installers/updates. Separate mentions in the content also refer to Phantom as an Android malware family, including references to Android click-fraud activity and ad-fraud behavior in game-mod distributions, but the supplied material does not provide enough detail to confidently merge all of these references into a single malware family. Because the name is reused across unrelated tooling, attribution, capabilities, infection vectors, and victimology should be interpreted carefully by context rather than assumed to refer to one unified malware strain.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

1 CVES
CVE-2018-13379Fortinet FortiOS SSL VPN Path Traversal Arbitrary File ReadExploited in the wild

Fortinet Secure Sockets Layer (SSL) VPN is vulnerable to unauthenticated directory traversal... Multiple malware campaigns have taken advantage of this vulnerability. The most notable being Cring ransomware (also known as Crypt3, Ghost, Phantom, and Vjszy1lo).

via ic3 alertsic3.gov
THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
NSO Group

That spyware system, dubbed “Phantom,” was offered secretly to U.S. government agencies by the NSO Group... During a presentation to officials in Washington, the company demonstrated a new system, called Phantom, that could hack any number in the United States that the F.B.I. decided to target.

via gizmodogizmodo.com
MITRE ATT&CK

Techniques & procedures

7 distinct techniques documented for this family, organized by ATT&CK tactic.

Persistence

1 technique
T1505.003Web ShellEvidence1

inject and run a DLL inside the memory space of the w3wp.exe worker pool process

T1055Process InjectionEvidence1

...uses reflective loading techniques to inject and run a DLL inside the memory space of the w3wp.exe worker pool process. | Phantom is project created to perform loading and executing .NET assemblies directly in memory within an IIS environment running in full-trust mode.

Stealth

3 techniques
T1036MasqueradingEvidence1
TacticStealth

"Standalone apps on Google Play... embed modules like Nova clicker"; "Google removed these after notification"

T1055Process InjectionEvidence1

...uses reflective loading techniques to inject and run a DLL inside the memory space of the w3wp.exe worker pool process. | Phantom is project created to perform loading and executing .NET assemblies directly in memory within an IIS environment running in full-trust mode.

T1620Reflective Code LoadingEvidence2
TacticStealth

Phantom is project created to perform loading and executing .NET assemblies directly in memory within an IIS environment running in full‑trust mode. Instead of relying on file‑based approach, it uses reflective loading techniques to inject and run a DLL inside the memory space of the w3wp.exe worker pool process

Credential Access

2 techniques
T1056Input CaptureEvidence1

Israel-based NSO Group develops Pegasus, a spyware that allows its government customers near-unfettered access to a victim’s device, including their personal data and their location.

T1212Exploitation for Credential AccessEvidence1

Pegasus is a so-called zero-click hacking tool that can invade a target’s mobile phone and extract messages, photos, contacts, messages and video recordings.

Collection

2 techniques
T1005Data from Local SystemEvidence1

Pegasus is a so-called zero-click hacking tool that can invade a target’s mobile phone and extract messages, photos, contacts, messages and video recordings.

T1056Input CaptureEvidence1

Israel-based NSO Group develops Pegasus, a spyware that allows its government customers near-unfettered access to a victim’s device, including their personal data and their location.

INDICATORS OF COMPROMISE

IOCs tracked for this family

3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
1 tracked

IPs, domains, and DNS infrastructure linked to this family.

Other
2 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
ip.v4●●●●●●●●●●●●View more in app2 days ago
uri●●●●●●●●●●●●View more in app1 month ago
uri●●●●●●●●●●●●View more in app8 months ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching3

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities1

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping7

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.