Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors PhantomControl

Description

PhantomControl is a sophisticated threat actor that emerged in November 2023. They utilize phishing emails as their initial infection vector and employ a ScreenConnect client to establish a connection for their malicious activities. Their arsenal includes a VBS script that hides its true intentions and reveals a complex mechanism involving PowerShell scripts and image-based data retrieval. PhantomControl has been associated with the Blind Eagle threat actors, showcasing their versatility and reach.

AI Analysis

· 1 week ago

Executive Summary

PhantomControl is a sophisticated threat actor emerging in late 2023, employing phishing and remote access tools to target victims. Their activities suggest potential ties to other groups like Blind Eagle, indicating a versatile operational capability focused on espionage or financial gain.

Goals & Targeting

PhantomControl's strategic objectives appear to focus on intelligence gathering and financial gain, targeting sectors such as finance, healthcare, and critical infrastructure. Their use of sophisticated malware suggests they target organizations with high-value data or those operating in industries prone to large-scale impact. The actor's geographic reach remains unclear but their association with Blind Eagle indicates a potential Middle Eastern or Eastern European origin.

Enhanced Description

PhantomControl operates with advanced tactics, leveraging phishing emails as their initial infection vector. They deploy the ScreenConnect client for command and control (C2), alongside a VBS script that conceals malicious activity through PowerShell execution and image-based data retrieval mechanisms. This combination highlights their technical proficiency in creating stealthy malware architectures. Associated with Blind Eagle, PhantomControl demonstrates versatility across campaigns, adapting their tools to avoid detection while maintaining a persistent presence on compromised systems.

Key Capabilities

  • Phishing emails as initial infection vector
  • ScreenConnect client for C2 communication
  • VBS script-based malware with embedded PowerShell functionality
  • Image-based data retrieval mechanisms
  • Use of remote access tools for persistence

MITRE ATT&CK Tactics

Initial Access
Execution
Defense Evasion
Discovery
Lateral Movement

ATT&CK Techniques

T1059.003
T1055
T1284.001
T1077.001
T1068.001

Software / Tooling

ScreenConnect
VBS script malware
Phishing emails
Custom Powershell scripts
Image-based data retrieval tool (possibly custom)

Campaigns & Victims

PhantomControl's campaigns demonstrate a focus on stealth and persistence, with victims likely experiencing prolonged compromises undetected. Their modus operandi includes the use of legitimate tools like Remote Desktop Services for lateral movement, making them challenging to detect without advanced monitoring. Campaigns may involve targeting high-value assets within financial institutions or critical infrastructure sectors.

IOC Patterns

  • Spear-phishing emails mimicking trusted entities
  • ScreenConnect client activity on compromised systems
  • Base64-encoded data within VBS scripts
  • Image files containing embedded malicious payloads
  • Phishing URLs redirecting to malicious domains

Recommended Actions

  • Implement multi-factor authentication (MFA) for critical systems
  • Educate users about phishing red flags and suspicious emails
  • Monitor for unusual remote desktop activity and lateral movement
  • Deploy endpoint detection and response (EDR) solutions
  • Review and update email filtering policies to detect malicious attachments

Suggested Tags

APT
espionage
financial-fraud
cyber-espionage
ransomware
critical-infrastructure-targeting
financial-sector

Confidence Assessment

Medium confidence due to limited public reporting, but their operational techniques and toolset align with known APT behaviors. Further intelligence on their exact motivations and geographic targeting is needed.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Phishing
APT
espionage
financial-fraud
cyber-espionage
ransomware
critical-infrastructure-targeting
financial-sector

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.