Skip to content

Phantom

Phantom is a malware name used for multiple unrelated threats, but the strongest malware-specific evidence here supports Phantom as a Windows information stealer.

Profile source: Mallory opens in a new tab

Phantom

Family profile

Phantom is a malware name used for multiple unrelated threats, but the strongest malware-specific evidence here supports Phantom as a Windows information stealer. It has been observed delivered by fake Adobe update or installer lures and is associated with social-engineering-driven infection chains. Reported behavior includes theft of sensitive user data and exfiltration of stolen information over SMTP. Phantom has also been referenced alongside other commodity stealers in criminal distribution ecosystems and has been used as a payload delivered by other malware loaders. Separately, the name Phantom has also been used in public reporting for an NSO Group phone-hacking product described as functionally aligned with Pegasus and marketed to U.S. government customers, but that usage refers to a mercenary spyware platform rather than the commodity infostealer activity most directly supported for this malware entry. Because the same name is applied to distinct tools, attribution, platforming, and capability claims beyond the stealer activity should be treated cautiously unless further disambiguated.

Capabilities

  • Credential Theft
  • Exfiltration

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 26, 2026
Last activity
Aug 27, 2026
Feed role
C2
Host form
0 IP / 7 hostnames

Leading locations

  • US2

Leading providers

  • Cloudflare, Inc.2

Infrastructure traits

  • Anycast 2
  • Hosting 2

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
NSO Group

That spyware system, dubbed “Phantom,” was offered secretly to U.S. government agencies by the NSO Group... During a presentation to officials in Washington, the company demonstrated a new system, called Phantom, that could hack any number in the United States that the F.B.I. decided to target.

Exploited software

Vulnerabilities linked to Phantom

1 CVEs

MITRE ATT&CK

Phantom in ATT&CK

19 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.