Skip to main content
Mallory
MalwareUsed by 1 actor

PhantomNet

PhantomNet, also referred to as DOWNTOWN and described in one source as SManager, is a remote access trojan/backdoor used in cyberespionage operations. Reported capabilities include collecting victim information, command-and-control communications, file read/write functionality, and installing or loading additional malicious plugins/payloads. It has been observed deployed via DLL sideloading and via trojanized software packages, including in a supply-chain compromise involving the Vietnam Government Certification Authority website, where post-compromise plugins were deployed using PhantomNet. Sophos observed multiple PhantomNet backdoor samples in the Crimson Palace intrusion set, including sslwnd64.exe, oci.dll, and nethood.exe, used for C2 communications and payload loading. PhantomNet has been linked in public reporting to Chinese state-aligned activity: Elastic associated DOWNTOWN/PhantomNet with the Chinese-nexus actor REF5961, Sophos reported overlaps between PhantomNet use and Cluster Alpha activity assessed with high confidence to support Chinese state interests, and other reporting cited in the content attributes PhantomNet to TA428 and notes Worok’s use of shared espionage toolsets including PhantomNet. Targeting mentioned in the content includes high-profile Southeast Asian government organizations and broader espionage-focused operations.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
TA428

PhantomNet (aka SManager, DOWNTOWN) is a simple backdoor capable of collecting victim information and installing malicious plugins that has been previously attributed to Chinese APT TA428.

via sophos threat researchnews.sophos.com
MITRE ATT&CK

Techniques & procedures

8 distinct techniques documented for this family, organized by ATT&CK tactic.

Execution

1 technique
T1574.001DLLEvidence1

The actor was then seen attempting a known DLL hijacking technique, phantom DLL sideloading. By placing the malicious oci.dll in a location read by the MSDTC service’s executable—a location the file does not usually occur in—the malicious code was called when the service was stopped and restarted

Persistence

1 technique
T1543.003Windows ServiceEvidence1

Following the deployment in March of a copy of a legitimate version of vmnat.exe ... the actor was observed creating registry keys to establish persistence.

T1543.003Windows ServiceEvidence1

Following the deployment in March of a copy of a legitimate version of vmnat.exe ... the actor was observed creating registry keys to establish persistence.

Stealth

4 techniques
T1036MasqueradingEvidence1
TacticStealth

The attacker created two DLLs (swprvs.dll and appmgmt.dll)... An ‘s’ was added to the filename of the legitimate swprv.dll and the ‘s’ was removed from the legitimate appmgmts.dll.

T1140Deobfuscate/Decode Files or InformationEvidence1
TacticStealth

the HUI loader (msedge_elf.dll), which de-obfuscated the file log.ini to reveal a Cobalt Strike reflective Loader

T1218System Binary Proxy ExecutionEvidence1
TacticStealth

the actor frequently abused endpoint protection software binaries to sideload their malicious payloads.

T1574.001DLLEvidence1

The actor was then seen attempting a known DLL hijacking technique, phantom DLL sideloading. By placing the malicious oci.dll in a location read by the MSDTC service’s executable—a location the file does not usually occur in—the malicious code was called when the service was stopped and restarted

T1071.001Web ProtocolsEvidence1

setDesktopMonitorHook function, which establishes communications with the domain cloud.keepasses[.]com ... PowHeartBeat backdoor ... connect to msudapis[.]info over port 443

T1090.002External ProxyEvidence1

the actor created a SOCKS proxy to be used by the Microsoft Distributed Transaction Coordinator (MSDTC) service

Exfiltration

1 technique
T1041Exfiltration Over C2 ChannelEvidence1

Throughout the intrusion, the actor in Cluster Alpha leveraged the PhantomNet implants ... to establish C2 communications and load additional payloads... PowHeartBeat ... now known to be an exfiltration domain.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping8

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.