Netskope Threat Labs

Phantomcore

ATP Sandbox Adv. HeuristicsAV

PhantomCore is a backdoor used by the hacktivist group Head Mare, active since 2023 and known for consistently targeting Russian organizations. It collects victim information to profile the target before deploying final stage payloads or running commands, and researchers observed it deploying ransomware payloads such as LockBit and Babuk.

First seen
October 2024
Last seen
October 2026
PhantomCore
Alert Name
Trojan.PhantomCore.2
Trojan.PhantomCore.3
Win64.Backdoor.Phantomcore
Win64.Trojan.Phantomcore
Win64.Trojan.PhantomCore