PULSE NAME
Expect guests : PhantomCore's new tools and tactics in attacks on Russian companies
WHITE PhantomCore PetrP.73 2026-04-26 Modified: 2026-05-26
42
IOCs
MEDIUM VOLUME
PhantomCore, a cybercrime group identified as a significant threat to Russian and Belarusian firms, has evolved its tactics and tools since its initial attacks were detected around 2022. This group's ability to adapt and innovate in response to evolving cybersecurity landscapes is notable. Among its latest developments is the proprietary malware KermitRAT, designed for remote access, which exhibits diverse functionalities including command execution, data exfiltration, and detailed system information gathering. The malware can execute hidden commands via PowerShell or cmd, capture screenshots, and log keystrokes, all of which are stealthily transmitted to the attackers' command and control (C2) servers.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (42)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 43ed7ce263151ae976bafbad3bc17742 2026-04-26
FileHash-SHA1 03f426e4d9928ae5a2236aea8604e208039d4f25 2026-04-26
FileHash-SHA256 6255425f2d1ab8741a1381853519db79f2e0ca083ceae6a415bd954d3a7d39f3 2026-04-26
FileHash-MD5 05fa2a9db255f37140e6716de4cf1716 2026-04-26
FileHash-SHA1 89673f31d51fca9f2aebaf3d654d5b9f812186f2 2026-04-26
FileHash-SHA256 f795725f53dbb711ac43d49032d2b64b3721e9036c760d531281a0a2767e4fd4 2026-04-26
FileHash-MD5 8e674f0379dda936208a365760074b11 2026-04-26
FileHash-SHA1 ea6d35dd96c7bf3ff7c51bb1dabb49db55648196 2026-04-26
FileHash-SHA256 6d294b99742c673c07e74c1ccaead44a80f50511576bc9977079aed4b76231ee 2026-04-26
FileHash-MD5 0ac3839a2b23b9b96b63c650bf8f6530 2026-04-26
FileHash-MD5 3f039e92637c8d4169960e878d091f04 2026-04-26
FileHash-MD5 86360fa1d33f8c2bd84607ab736123cf 2026-04-26
FileHash-MD5 96d00bf02e6b3c70f6b6e0d524a1dc0d 2026-04-26
FileHash-MD5 b1be02032c6e3ebefc467b5d0dd3ee07 2026-04-26
FileHash-MD5 b22c21f19ab6d796df84b70d204804b4 2026-04-26
FileHash-MD5 c65acfc2720de2a940c5f24cd98055fa 2026-04-26
FileHash-MD5 ce8e7a3fa0b38165d60f4688e69490ce 2026-04-26
FileHash-MD5 fbd9910e36b07c6d4a095c8aabc2c801 2026-04-26
FileHash-SHA1 1148dc9cd85c90aff2307e3d2ec8ba9bfe6a2413 2026-04-26
FileHash-SHA1 267a1282c08fe1240e6f3d68396596e4cdb69b56 2026-04-26
FileHash-SHA1 573e190020441283e99f27b7a62fe5d74d944dc0 2026-04-26
FileHash-SHA1 6d79675d5d2df4d0b6c6e6c29502f7cad9cd9110 2026-04-26
FileHash-SHA1 92c2701a8f15a45a5f3d6be1482f5af6851eb2a1 2026-04-26
FileHash-SHA1 96c2c70300d0734c6993ddb6ed1214c5ae9c198b 2026-04-26
FileHash-SHA1 d3fcabc6a90c79aff24ea71c571484de74f631cd 2026-04-26
FileHash-SHA1 e4181463896b2f0f1d7daa353ae661e180407c71 2026-04-26
FileHash-SHA1 fc5d8c3adade2bd27269d86a3883c6d9518e8836 2026-04-26
FileHash-SHA256 2679aaaa61a0d4270cc35c4a45d1717b04da17965269a2ae66bc4564f5582596 2026-04-26
FileHash-SHA256 30918f193ddb02c46419928aab5ce1acc01544f20185190d40567041abbf980a 2026-04-26
FileHash-SHA256 660cb702830fc38c7981ea1b55f45679460452bc731d4f7acc36b14095682919 2026-04-26
FileHash-SHA256 73f5db0b04dfff8274ecb96dc3c10c8d4819627a20110dc763123d6ed3421fa9 2026-04-26
FileHash-SHA256 79f027c533d8cf563c3cddf3744651a674d0dc03d56b932156806bcdb102c8d9 2026-04-26
FileHash-SHA256 992cc3c6c3af7c7b443e59038864ab89e7f78a5ab3de517477f136072b4b38e3 2026-04-26
FileHash-SHA256 b4fa704eca8fad7e56e172c1bf7282248d3a058250cdb0bdfd493c979c03b11f 2026-04-26
FileHash-SHA256 bfac106c163b1e04eea4ec0bf2d46b2b4296130e660d335d1d9f44c3ddc89321 2026-04-26
FileHash-SHA256 d687509ed1e9e0a073a30e1a7fd1fb96ffc06c92858356202c7bd9a06d76d822 2026-04-26
URL http://94.183.183.69:3000/ 2026-04-26
URL https://realty-visual.ru/jk_strana_ozernaya/4gotovii_spisok_sotrudnikov_dlya_posejenia_meropriyatia.txt 2026-04-26
URL https://realty-visual.ru/jk_strana_ozernaya/5fulltext_spisok_sotrudnikov_dlya_posejenia_meropriyatia.txt 2026-04-26
URL https://realty-visual.ru/jk_strana_ozernaya/KNDR_2026.pdf 2026-04-26
domain ministerstvo-inostrannykh-del.ru 2026-04-26
domain realty-visual.ru 2026-04-26