PULSE NAME
Expect guests : PhantomCore's new tools and tactics in attacks on Russian companies
WHITE PhantomCore PetrP.73 2026-04-26 Modified: 2026-05-26
42
IOCs
MEDIUM VOLUME
PhantomCore, a cybercrime group identified as a significant threat to Russian and Belarusian firms, has evolved its tactics and tools since its initial attacks were detected around 2022. This group's ability to adapt and innovate in response to evolving cybersecurity landscapes is notable. Among its latest developments is the proprietary malware KermitRAT, designed for remote access, which exhibits diverse functionalities including command execution, data exfiltration, and detailed system information gathering. The malware can execute hidden commands via PowerShell or cmd, capture screenshots, and log keystrokes, all of which are stealthily transmitted to the attackers' command and control (C2) servers.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (12 / 42 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 43ed7ce263151ae976bafbad3bc17742 2026-04-26
FileHash-MD5 05fa2a9db255f37140e6716de4cf1716 2026-04-26
FileHash-MD5 8e674f0379dda936208a365760074b11 2026-04-26
FileHash-MD5 0ac3839a2b23b9b96b63c650bf8f6530 2026-04-26
FileHash-MD5 3f039e92637c8d4169960e878d091f04 2026-04-26
FileHash-MD5 86360fa1d33f8c2bd84607ab736123cf 2026-04-26
FileHash-MD5 96d00bf02e6b3c70f6b6e0d524a1dc0d 2026-04-26
FileHash-MD5 b1be02032c6e3ebefc467b5d0dd3ee07 2026-04-26
FileHash-MD5 b22c21f19ab6d796df84b70d204804b4 2026-04-26
FileHash-MD5 c65acfc2720de2a940c5f24cd98055fa 2026-04-26
FileHash-MD5 ce8e7a3fa0b38165d60f4688e69490ce 2026-04-26
FileHash-MD5 fbd9910e36b07c6d4a095c8aabc2c801 2026-04-26