PhantomGraph is a Windows two-component backdoor associated with the Head Mare threat actor. Its communication component retrieves attacker commands through Microsoft OneDrive, while its execution component processes those commands, executes them on the compromised host, stores execution output, and returns results through the OneDrive-based command-and-control channel. The components have been installed as Windows services, providing persistence. PhantomGraph has been deployed following compromise of TrueConf Server instances, including alongside the PhantomCore backdoor, in campaigns targeting Russian organizations in instrumentation, electronics, transportation, energy, IT, and software-development sectors. Observed related activity includes host and user reconnaissance, LSASS memory dumping for credential theft, and establishment of reverse SSH tunnels.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Head Mare also deploys PhantomGraph, another backdoor consisting of SysExcSvc.dll and SysReadSvc.dll, capable of receiving commands through a Microsoft OneDrive account.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
the attackers exploited a chain of vulnerabilities in the TrueConf video conferencing server... The attackers connect to the TrueConf server without prior authorization via port 4307/TCP... attackers call a server function to transmit a malicious script and execute it on the server.
The attackers distribute their backdoors using various methods, including phishing, exploiting public web servers, or through a subcontractor.
[The vulnerabilities] allowed the attackers to run a malicious script ... and execute commands on the underlying operating system.
Head Mare, now assessed as an APT group, exploited two vulnerabilities in unpatched TrueConf video conferencing servers to achieve SYSTEM-level code execution and deploy a web shell.
/etc/systemd/system/omicluster.service /etc/systemd/system/schedul2-bin.service
Both components establish persistence on the server by creating services with the names SysExcSvc and SysReadSvc.
To escape the isolated environment, attackers exploit a second vulnerability... Exploiting this vulnerability allows them to bypass the restrictions of the isolated environment and proceed to execute commands in the context of the operating system... with the privileges of the NT AUTHORITY\SYSTEM account.
/etc/systemd/system/omicluster.service /etc/systemd/system/schedul2-bin.service
Both components establish persistence on the server by creating services with the names SysExcSvc and SysReadSvc.
The attackers used an account on Microsoft OneDrive cloud storage as their command-and-control (C2) server.
Exfiltration and C2 communications were conducted over both custom malicious domains and IP addresses, as well as via OneDrive cloud storage.
The attackers use a Microsoft OneDrive cloud storage account as the command and control (C&C) server... on *nix systems, the attackers install a backdoor that uses GitHub as a command and control channel.
PhantomGraph ... is capable of receiving commands through a Microsoft OneDrive account, executing these commands and returning the results.
41 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A two-DLL backdoor that uses a Microsoft OneDrive account for command-and-control, executes received commands, returns results, supports LSASS memory dumping for credential theft, reconnaissance, and reverse SSH tunneling.
Named in the indicators/detection section as Trojan.Win64.PhantomGraph, with an MD5 hash provided, but not otherwise described in the content.
A malware payload delivered in the TrueConf server intrusion campaign attributed to Head Mare.
A backdoor used on compromised TrueConf servers as a backup command-and-control channel, consisting of communication and execution modules that use Microsoft OneDrive for C2 and persist via the SysExcSvc and SysReadSvc services.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.