TF-MAL-ps1.phantom_relay
📛 Threat Title
Malware family: PhantomRelay
Description
ThreatFox malware family `ps1.phantom_relay`. Printable name: PhantomRelay.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:alpha-cyber.com
RegPhantom Rootkit Alert - Suspicious Activity Detected Hash 703dfb12…e7c4 is flagged as suspicious and potentially linked to RegPhantom rootkit activity, with a risk score of 69/100. The assessment carries 80% confidence, making it suitable for immediate triage and deeper investigation.
-
web:github.com
Phantom Loader is a proof-of-concept (PoC) shellcode loader and initial access framework developed to demonstrate how a sophisticated threat actor could achieve stealthy initial access against a Windows enterprise environment while evading modern endpoint defenses. The malware bundle is packaged to ...
-
web:github.com
🕵️♂️ Malware Analysis: Phantom Stealer V3 ⚠️ Disclaimer This repository is for educational and research purposes only. The analysis details a real-world malware sample found in the wild. I am not responsible for any damage caused by the misuse of this information. The malicious binary is NOT included in this repository.
-
web:malpedia.caad.fkie.fraunhofer.de
The family includes several variants, such as PhantomRelayLite and PhantomRelayV1/V2, which feature progressive obfuscation and persistence enhancements. The operators are Russian-speaking and Moscow-time aligned, with the tooling observed across GREYVIBE-related campaigns and related cybercrime activity.
-
web:malpedia.caad.fkie.fraunhofer.de
This page gives an overview of all malware families that are covered on Malpedia, supplemented with some basic information for each family .
-
web:radar.offseq.com
Mitigation Recommendations No official patch or remediation is indicated for this malware family as it is a threat actor tool rather than a software vulnerability. Mitigation should focus on detection and removal using updated endpoint security solutions capable of identifying kernel-level rootkits and backdoors.
-
web:windowsforum.com
The more durable remediation is to prove that Defender engine and security intelligence updates flow reliably across the environment. CVE-2026-41091 is a reason to audit that pipeline, not merely to check one version once.
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.mallory.ai
PhantomRelay is a modular PowerShell-based remote access trojan (RAT) used by the GREYVIBE threat actor in campaigns targeting Ukraine and broader Eastern European entities since at least August 2025. It is described as a two-stage implant consisting of an initial fingerprinting script followed by the main RAT client.
-
web:www.webpronews.com
WithSecure details GREYVIBE, a Russia-nexus cluster using ChatGPT and Gemini for lures, custom malware like PhantomRelay and LegionRelay, and espionage against Ukrainian targets since August 2025. The group blends cybercrime ties with state-aligned goals.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.