Positive Technologies reported that PhantomCore conducted a large-scale cyberespionage campaign using a mix of phishing, compromised corporate email accounts, malicious attachments and links, and in some cases exploitation of a TrueConf vulnerability chain tracked as BDU:2025-10114, BDU:2025-10115, and BDU:2025-10116. The group was observed deploying a substantial custom toolset including PhantomRAT, PhantomRShell, PhantomTaskShell, PhantomProxyLite, PhantomStealer, and a dedicated control panel, while also abusing legitimate software such as MeshAgent, OpenSSH, Rclone, and XenArmor. Researchers said the activity may indicate a split within the PhantomCore APT group.
After gaining access, the attackers established persistence with disguised scheduled tasks, services, local accounts, and web shells, then stole credentials from LSASS and NTDS, moved laterally over RDP, SMB, and WinRM, and masked operations with obfuscated PowerShell, DLL hijacking, disabled defenses, and cleared logs. Their command-and-control infrastructure used phishing domains, VPS hosts, compromised servers, SSH and SOCKS5 tunnels, HTTPS, and nonstandard ports, with data exfiltration carried out through HTTP channels, external servers, and cloud storage including Mega.nz. In at least one intrusion, the operation escalated from espionage to destructive impact when PhantomCore used Kaspersky Security Center to distribute LockBit 3.0 ransomware across compromised systems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
A later Positive Technologies report says PhantomCore used active scanning, a chain of TrueConf vulnerabilities (BDU:2025-10114, BDU:2025-10115, BDU:2025-10116), spearphishing with malicious LNK files, and legitimate administration tools to expand access. The intrusion culminated in credential dumping, lateral movement, exfiltration over C2 channels, and deployment of LockBit 3.0 ransomware on compromised systems.
Positive Technologies' global report details PhantomCore's full intrusion lifecycle, including phishing-based initial access, persistence through scheduled tasks, credential theft, segmented command-and-control infrastructure, and exfiltration to external servers and Mega.nz. This publication consolidates technical details on the group's malware ecosystem and operational methods.
Positive Technologies describes PhantomCore as running a broad cyberespionage campaign using phishing through compromised corporate email accounts, custom malware families such as PhantomRAT and PhantomRShell, lateral movement via RDP/SMB/WinRM, and data theft using tools including PhantomStealer and Rclone. The reporting also raises the possibility of a split within the PhantomCore APT group.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
ptsecurity.com
Open sourceglobal.ptsecurity.com
Open sourcehabr.com
Open sourceptsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.