Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
PhantomCore exploits a variation of CVE-2023-38831 using RAR archives instead of ZIP archives. In WinRAR versions earlier than 6.23, attempting to open the enclosed PDF launches a malicious executable from a same-named directory.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Данная библиотека содержит функциональные возможности для загрузки и записи файла в систему ... а также закрепления загруженного файла в системе, путем создания запланированной задачи. Далее по тексту данное вредоносное ПО будет иметь название PhantomCore.Downloader.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
«Закрепление в зараженной системе выполняется путем создания запланированной задачи.»
«PhantomCore используют вредоносное ПО PhantomRAT, которое может использовать cmd.exe для выполнения команд на зараженной системе.»
«Группа использует .NET-приложения с опцией развертывания одним файлом (single-file deployment) для затруднения обнаружения на зараженной системе.»
«Создает запланированную задачу с именем MicrosoftStatisticCore.»
25 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Earlier, relatively simple downloader used by PhantomCore to retrieve PhantomRAT. In the group's first known January 2024 attack, it was packaged in a password-protected archive named 'Информация по договору.rar'. The report describes the subsequent adoption of PhantomDL as an evolution of the group's tooling.
First-stage .NET downloader used by PhantomCore to install PhantomRAT. Password-protected phishing RAR archives exploit CVE-2023-38831 in WinRAR versions earlier than 6.23, causing an executable disguised as a PDF to run when the victim opens the apparent document. The single-file executable contains the malicious service.dll module, downloads PhantomRAT from FileTransfer.io, and writes it beneath %AppData%\Microsoft\Windows\. It establishes persistence through a scheduled task named MicrosoftStatisticCore, which launches the payload through pcalua.exe. Apparent test samples were first uploaded to VirusTotal on January 31, 2024; this is an upload date, not an explicitly established discovery date.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.