PULSE NAME
Expect guests : PhantomCore's new tools and tactics in attacks on Russian companies
WHITE PhantomCore PetrP.73 2026-04-26 Modified: 2026-05-26
42
IOCs
MEDIUM VOLUME
PhantomCore, a cybercrime group identified as a significant threat to Russian and Belarusian firms, has evolved its tactics and tools since its initial attacks were detected around 2022. This group's ability to adapt and innovate in response to evolving cybersecurity landscapes is notable. Among its latest developments is the proprietary malware KermitRAT, designed for remote access, which exhibits diverse functionalities including command execution, data exfiltration, and detailed system information gathering. The malware can execute hidden commands via PowerShell or cmd, capture screenshots, and log keystrokes, all of which are stealthily transmitted to the attackers' command and control (C2) servers.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (12 / 42 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 03f426e4d9928ae5a2236aea8604e208039d4f25 2026-04-26
FileHash-SHA1 89673f31d51fca9f2aebaf3d654d5b9f812186f2 2026-04-26
FileHash-SHA1 ea6d35dd96c7bf3ff7c51bb1dabb49db55648196 2026-04-26
FileHash-SHA1 1148dc9cd85c90aff2307e3d2ec8ba9bfe6a2413 2026-04-26
FileHash-SHA1 267a1282c08fe1240e6f3d68396596e4cdb69b56 2026-04-26
FileHash-SHA1 573e190020441283e99f27b7a62fe5d74d944dc0 2026-04-26
FileHash-SHA1 6d79675d5d2df4d0b6c6e6c29502f7cad9cd9110 2026-04-26
FileHash-SHA1 92c2701a8f15a45a5f3d6be1482f5af6851eb2a1 2026-04-26
FileHash-SHA1 96c2c70300d0734c6993ddb6ed1214c5ae9c198b 2026-04-26
FileHash-SHA1 d3fcabc6a90c79aff24ea71c571484de74f631cd 2026-04-26
FileHash-SHA1 e4181463896b2f0f1d7daa353ae661e180407c71 2026-04-26
FileHash-SHA1 fc5d8c3adade2bd27269d86a3883c6d9518e8836 2026-04-26