SYMBOLCOMMON_NAMEaka. SYNONYMS
win.phantomcore (Back to overview)

PhantomCore

VTCollection    

According to Cyble, PhantomCore is a backdoor utilized by the hacktivist group Head Mare. It has been active since 2023 and is known for consistently targeting Russia. PhantomCore collects the victim’s information, including the public IP address, to gain detailed insights into the target before deploying the final-stage payload or executing additional commands on the compromised system. PhantomCore is known to deploy ransomware payloads such as LockBit and Babuk, inflicting significant damage on the victim’s systems.

References
2026-08-07 ⋅ ⋅ Kaspersky ⋅ Kaspersky
The APT group Head Mare exploits vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph malware to video conferencing participants
PhantomCore PhantomGraph
2025-11-26 ⋅ Intrinsec ⋅ CTI Intrinsec, David Sardinha
Trouble in the air: A spree of campaigns targeting the aerospace industry in Russia
DarkWatchman CloudEyE Formbook PhantomCore Remcos
2025-09-23 ⋅ ⋅ F6 ⋅ F6
Bearlyfy: the evolution of the new group of ransomware and its connection with PhantomCore
LockBit LockBit PhantomCore Bearlyfy
2025-09-09 ⋅ Positive Technologies ⋅ Viktor Kazakov
Phantom pains: a large-scale cyberespionage campaign and a possible split within the PhantomCore APT group
PhantomCore
2024-12-10 ⋅ cyble ⋅ Cyble
Head Mare Group Intensifies Attacks on Russia with PhantomCore Backdoor
PhantomCore Head Mare
2024-09-02 ⋅ Kaspersky Labs ⋅ Kaspersky
Head Mare: adventures of a unicorn in Russia and Belarus
PhantomCore Head Mare
Yara Rules
[TLP:WHITE] win_phantomcore_auto (20260917 | Detects win.phantomcore.)
rule win_phantomcore_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.phantomcore."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.phantomcore"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 8b5a04 895f04 8b29 395504 743f 3913 7440 }
            // n = 7, score = 100
            //   8b5a04               | mov                 ebx, dword ptr [edx + 4]
            //   895f04               | mov                 dword ptr [edi + 4], ebx
            //   8b29                 | mov                 ebp, dword ptr [ecx]
            //   395504               | cmp                 dword ptr [ebp + 4], edx
            //   743f                 | je                  0x41
            //   3913                 | cmp                 dword ptr [ebx], edx
            //   7440                 | je                  0x42

        $sequence_1 = { e8???????? 894dcc 8b7d10 8b550c 8b4d08 8965e4 c745f0ffffffff }
            // n = 7, score = 100
            //   e8????????           |                     
            //   894dcc               | mov                 dword ptr [ebp - 0x34], ecx
            //   8b7d10               | mov                 edi, dword ptr [ebp + 0x10]
            //   8b550c               | mov                 edx, dword ptr [ebp + 0xc]
            //   8b4d08               | mov                 ecx, dword ptr [ebp + 8]
            //   8965e4               | mov                 dword ptr [ebp - 0x1c], esp
            //   c745f0ffffffff       | mov                 dword ptr [ebp - 0x10], 0xffffffff

        $sequence_2 = { 50 e8???????? 83c404 85c0 0f8407020000 89c1 83c023 }
            // n = 7, score = 100
            //   50                   | push                eax
            //   e8????????           |                     
            //   83c404               | add                 esp, 4
            //   85c0                 | test                eax, eax
            //   0f8407020000         | je                  0x20d
            //   89c1                 | mov                 ecx, eax
            //   83c023               | add                 eax, 0x23

        $sequence_3 = { 8b9610020000 8d4801 81f900100000 724c 8b4afc 83c2fc 29ca }
            // n = 7, score = 100
            //   8b9610020000         | mov                 edx, dword ptr [esi + 0x210]
            //   8d4801               | lea                 ecx, [eax + 1]
            //   81f900100000         | cmp                 ecx, 0x1000
            //   724c                 | jb                  0x4e
            //   8b4afc               | mov                 ecx, dword ptr [edx - 4]
            //   83c2fc               | add                 edx, -4
            //   29ca                 | sub                 edx, ecx

        $sequence_4 = { 83c404 e9???????? c745c047d84b00 c745c489ca4b00 c745c88b000000 c745cc27000000 c745d818714b00 }
            // n = 7, score = 100
            //   83c404               | add                 esp, 4
            //   e9????????           |                     
            //   c745c047d84b00       | mov                 dword ptr [ebp - 0x40], 0x4bd847
            //   c745c489ca4b00       | mov                 dword ptr [ebp - 0x3c], 0x4bca89
            //   c745c88b000000       | mov                 dword ptr [ebp - 0x38], 0x8b
            //   c745cc27000000       | mov                 dword ptr [ebp - 0x34], 0x27
            //   c745d818714b00       | mov                 dword ptr [ebp - 0x28], 0x4b7118

        $sequence_5 = { c745dc00000000 eb07 31d2 eb03 8b55e0 8b7508 8b4d0c }
            // n = 7, score = 100
            //   c745dc00000000       | mov                 dword ptr [ebp - 0x24], 0
            //   eb07                 | jmp                 9
            //   31d2                 | xor                 edx, edx
            //   eb03                 | jmp                 5
            //   8b55e0               | mov                 edx, dword ptr [ebp - 0x20]
            //   8b7508               | mov                 esi, dword ptr [ebp + 8]
            //   8b4d0c               | mov                 ecx, dword ptr [ebp + 0xc]

        $sequence_6 = { b36b e9???????? 89f8 40 bd04000000 bb???????? b263 }
            // n = 7, score = 100
            //   b36b                 | mov                 bl, 0x6b
            //   e9????????           |                     
            //   89f8                 | mov                 eax, edi
            //   40                   | inc                 eax
            //   bd04000000           | mov                 ebp, 4
            //   bb????????           |                     
            //   b263                 | mov                 dl, 0x63

        $sequence_7 = { c745c870617273 c745cc655f6572 c745cf72726f72 c645d300 c745f001000000 8d45c8 8d4d80 }
            // n = 7, score = 100
            //   c745c870617273       | mov                 dword ptr [ebp - 0x38], 0x73726170
            //   c745cc655f6572       | mov                 dword ptr [ebp - 0x34], 0x72655f65
            //   c745cf72726f72       | mov                 dword ptr [ebp - 0x31], 0x726f7272
            //   c645d300             | mov                 byte ptr [ebp - 0x2d], 0
            //   c745f001000000       | mov                 dword ptr [ebp - 0x10], 1
            //   8d45c8               | lea                 eax, [ebp - 0x38]
            //   8d4d80               | lea                 ecx, [ebp - 0x80]

        $sequence_8 = { 8d7d08 8965e4 c745f0ffffffff 8d45e8 c745ec80ae4400 648b0d00000000 894de8 }
            // n = 7, score = 100
            //   8d7d08               | lea                 edi, [ebp + 8]
            //   8965e4               | mov                 dword ptr [ebp - 0x1c], esp
            //   c745f0ffffffff       | mov                 dword ptr [ebp - 0x10], 0xffffffff
            //   8d45e8               | lea                 eax, [ebp - 0x18]
            //   c745ec80ae4400       | mov                 dword ptr [ebp - 0x14], 0x44ae80
            //   648b0d00000000       | mov                 ecx, dword ptr fs:[0]
            //   894de8               | mov                 dword ptr [ebp - 0x18], ecx

        $sequence_9 = { 8b8660020000 39d8 8b7d08 0f82450d0000 8b4f08 8b39 8b4904 }
            // n = 7, score = 100
            //   8b8660020000         | mov                 eax, dword ptr [esi + 0x260]
            //   39d8                 | cmp                 eax, ebx
            //   8b7d08               | mov                 edi, dword ptr [ebp + 8]
            //   0f82450d0000         | jb                  0xd4b
            //   8b4f08               | mov                 ecx, dword ptr [edi + 8]
            //   8b39                 | mov                 edi, dword ptr [ecx]
            //   8b4904               | mov                 ecx, dword ptr [ecx + 4]

    condition:
        7 of them and filesize < 1840128
}
Download all Yara Rules