Skip to content

Hide Navigation Hide TOC

PHANTOMNET (f97ea150-a727-4d47-823a-41de07a43ea9)

PHANTOMNET is a modular backdoor that communicates using a custom communication protocol over TCP. PHANTOMNET's core functionality involves expanding its capabilities through a plugin management system. The downloaded plugins are mapped directly into memory and executed.

Cluster A Galaxy A Cluster B Galaxy B Level
UNC5330 (c5ea778c-df2f-4c63-b401-dded9cb2419c) Threat Actor PHANTOMNET (f97ea150-a727-4d47-823a-41de07a43ea9) Backdoor 1
TONERJAM (540b3e66-edbf-40ee-ae05-474b27c1ff40) Tool PHANTOMNET (f97ea150-a727-4d47-823a-41de07a43ea9) Backdoor 1
UNC5330 (c5ea778c-df2f-4c63-b401-dded9cb2419c) Threat Actor TONERJAM (540b3e66-edbf-40ee-ae05-474b27c1ff40) Tool 2
UNC5330 (c5ea778c-df2f-4c63-b401-dded9cb2419c) Threat Actor GOST (c9f26173-ba82-4ed2-adbd-e2e07f582f31) Tool 2