Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
PhantomCore uploads PhantomTaskShell to directories on compromised legitimate sites.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
PhantomCore gains access to servers of legitimate sites and later uses them to store samples of MeshAgent, PhantomTaskShell, and Rsocx
PhantomCore creates Windows Task Scheduler tasks on infected hosts: to run SSH tunnels and MeshAgent samples at 09:00–10:00, disguising task names as legitimate software updates and system services... to run PhantomTaskShell for 9,999 days... disguised as an admin service named SystemAdminAgent_<GUID>
PhantomCore creates Windows Task Scheduler tasks on infected hosts: to run SSH tunnels and MeshAgent samples at 09:00–10:00, disguising task names as legitimate software updates and system services... to run PhantomTaskShell for 9,999 days... disguised as an admin service named SystemAdminAgent_<GUID>
PhantomCore creates Windows Task Scheduler tasks on infected hosts: to run SSH tunnels and MeshAgent samples at 09:00–10:00, disguising task names as legitimate software updates and system services... to run PhantomTaskShell for 9,999 days... disguised as an admin service named SystemAdminAgent_<GUID>
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.