phantom

First seen
2017-11-10 00:00:00
Malware type
trojan, rat
Family
Malware family
Last IoC activity
2026-07-22 02:04:33
Profile updated
2026-07-07 13:57:00

Targeted industries: government-and-public-sector energy-and-utilities financial-services

Targeted regions: country_code:us country_code:de

Context

Phantom is a remote access Trojan (RAT) known for targeting government, energy, and financial sectors. It is capable of providing attackers with complete control over the infected systems, enabling data exfiltration and persistent access.

Detection coverage

  • 1 YARA rules

Detection rules

  • DITEKSHEN_INDICATOR_RTF_Ancalog_Exploit_Builder_Document (yara-rule)

Reports & references

  • ransomlook.io — Phantom (report)

External references