PhantomControl

Primary motivation
espionage
Sophistication
advanced
Resource level
organization
Actor type
nation-state
Profile updated
2026-07-07 12:11:27

Targeted industries: government-and-public-sector technology-and-telecommunications financial-services

Context

PhantomControl is a sophisticated threat actor that emerged in November 2023. They utilize phishing emails as their initial infection vector and employ a ScreenConnect client to establish a connection for their malicious activities. Their arsenal includes a VBS script that hides its true intentions and reveals a complex mechanism involving PowerShell scripts and image-based data retrieval. PhantomControl has been associated with the Blind Eagle threat actors, showcasing their versatility and reach.

Reports & references

  • esentire.com — Phantomcontrol Returns With Ande Loader And Swaetrat (report)
  • esentire.com — Operation Phantomcontrol (report)
  • securityonline.info — Esentire Vs Phantom Unveiling The Cyber Spooks Dance Of Darkness (report)

External references