[ << ALL_FEED ]

Through phantom payments to confidential data

More in General

From Phantom Payments to Confidential Data 🫰

In June, we published an article about discovered Exchange keyloggers. At that time, nine victim companies were identified in Russia, but we did not perform any attribution then.

In July of this year, we made a time jump and returned to December 2024. Analysis of the attack recorded at that time allowed us to link a number of the discovered keyloggers to the PhantomCore 👻 group. Meanwhile, the total number of victims in Russia increased: there were nine in June of this year, and already 18 in August.

Here is the overall statistics:

• 10 companies out of the total number of compromised organizations are victims of the PhantomCore group.

• In total, over 5,000 lines of “login — password — login date” data were discovered, which the attackers obtained.

• The time jump allowed us to find a sample of the PhantomDL v3 malware that was used in attacks mimicking military jurisprudence.

You can find the analysis of the time jump in our new research on Habr.

P.S.: we are not done with PhantomCore. Stay tuned for updates 🔜

#TI #APT #Malware
@ptescalator

More from ti_author

More from ti_author

More in General