← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Expect guests : PhantomCore's new tools and tactics in attacks on Russian companies
PhantomCore, a cybercrime group identified as a significant threat to Russian and Belarusian firms, has evolved its tactics and tools since its initial attacks were detected around 2022. This group's ability to adapt and innovate in response to evolving cybersecurity landscapes is notable. Among its latest developments is the proprietary malware KermitRAT, designed for remote access, which exhibits diverse functionalities including command execution, data exfiltration, and detailed system information gathering. The malware can execute hidden commands via PowerShell or cmd, capture screenshots, and log keystrokes, all of which are stealthily transmitted to the attackers' command and control (C2) servers.
Indicators of Compromise (12 / 42 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-SHA1 | 03f426e4d9928ae5a2236aea8604e208039d4f25 | — | 2026-04-26 | |
| FileHash-SHA1 | 89673f31d51fca9f2aebaf3d654d5b9f812186f2 | — | 2026-04-26 | |
| FileHash-SHA1 | ea6d35dd96c7bf3ff7c51bb1dabb49db55648196 | — | 2026-04-26 | |
| FileHash-SHA1 | 1148dc9cd85c90aff2307e3d2ec8ba9bfe6a2413 | — | 2026-04-26 | |
| FileHash-SHA1 | 267a1282c08fe1240e6f3d68396596e4cdb69b56 | — | 2026-04-26 | |
| FileHash-SHA1 | 573e190020441283e99f27b7a62fe5d74d944dc0 | — | 2026-04-26 | |
| FileHash-SHA1 | 6d79675d5d2df4d0b6c6e6c29502f7cad9cd9110 | — | 2026-04-26 | |
| FileHash-SHA1 | 92c2701a8f15a45a5f3d6be1482f5af6851eb2a1 | — | 2026-04-26 | |
| FileHash-SHA1 | 96c2c70300d0734c6993ddb6ed1214c5ae9c198b | — | 2026-04-26 | |
| FileHash-SHA1 | d3fcabc6a90c79aff24ea71c571484de74f631cd | — | 2026-04-26 | |
| FileHash-SHA1 | e4181463896b2f0f1d7daa353ae661e180407c71 | — | 2026-04-26 | |
| FileHash-SHA1 | fc5d8c3adade2bd27269d86a3883c6d9518e8836 | — | 2026-04-26 |
References (1)