Through phantom payments to confidential data

More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
From Phantom Payments to Confidential Data 🫰
In June, we published an article about discovered Exchange keyloggers. At that time, nine victim companies were identified in Russia, but we did not perform any attribution then.
In July of this year, we made a time jump and returned to December 2024. Analysis of the attack recorded at that time allowed us to link a number of the discovered keyloggers to the PhantomCore 👻 group. Meanwhile, the total number of victims in Russia increased: there were nine in June of this year, and already 18 in August.
Here is the overall statistics:
• 10 companies out of the total number of compromised organizations are victims of the PhantomCore group.
• In total, over 5,000 lines of “login — password — login date” data were discovered, which the attackers obtained.
• The time jump allowed us to find a sample of the PhantomDL v3 malware that was used in attacks mimicking military jurisprudence.
You can find the analysis of the time jump in our new research on Habr.
P.S.: we are not done with PhantomCore. Stay tuned for updates 🔜
#TI #APT #Malware
@ptescalator
More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…



