phantom
- First seen
- 2017-11-10 00:00:00
- Malware type
- trojan, rat
- Family
- Malware family
- Last IoC activity
- 2026-07-22 02:04:33
- Profile updated
- 2026-07-07 13:57:00
Targeted industries: government-and-public-sector energy-and-utilities financial-services
Targeted regions: country_code:us country_code:de
Context
Phantom is a remote access Trojan (RAT) known for targeting government, energy, and financial sectors. It is capable of providing attackers with complete control over the infected systems, enabling data exfiltration and persistent access.
Detection coverage
- 1 YARA rules
Detection rules
- DITEKSHEN_INDICATOR_RTF_Ancalog_Exploit_Builder_Document (yara-rule)
Reports & references
- ransomlook.io — Phantom (report)