PhantomControl
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- organization
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:11:27
Targeted industries: government-and-public-sector technology-and-telecommunications financial-services
Context
PhantomControl is a sophisticated threat actor that emerged in November 2023. They utilize phishing emails as their initial infection vector and employ a ScreenConnect client to establish a connection for their malicious activities. Their arsenal includes a VBS script that hides its true intentions and reveals a complex mechanism involving PowerShell scripts and image-based data retrieval. PhantomControl has been associated with the Blind Eagle threat actors, showcasing their versatility and reach.
Reports & references
- esentire.com — Phantomcontrol Returns With Ande Loader And Swaetrat (report)
- esentire.com — Operation Phantomcontrol (report)
- securityonline.info — Esentire Vs Phantom Unveiling The Cyber Spooks Dance Of Darkness (report)