NuggetPhantom

First seen
2018-01-01 00:00:00
Malware type
rat, cryptominer
Family
Malware family
Profile updated
2026-07-07 15:14:03

Targeted industries: financial-services energy-and-utilities government-and-public-sector healthcare-and-pharmaceutical technology-and-telecommunications

Context

NSFOCUS describes PhantomNugget as a modularized malware toolkit, that was spread using EternalBlue. Payloads included a RAT and a XMRig miner.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Nugget Phantom (report)
  • staging.nsfocusglobal.com — Nuggetphantom Analysis Report V4.1 (report)
  • redcanary.com — Tracking Driver Inventory To Expose Rootkits (report)

External references