PhantomControl
0 incidentes
0 paises
0 sectores
apt IR Ultimo: -
PhantomControl is an Iranian-linked cyber espionage group assessed to have been active since at least 2018, primarily targeting government entities, critical infrastructure, and financial sectors. This highly targeted group is distinguished by its use of custom malware and exploitation of zero-day vulnerabilities in multi-stage attack operations. They are known for extensive reconnaissance and employing social engineering for initial access, and have demonstrated a consistent focus on maintaining persistence and evading detection. PhantomControl shares operational characteristics with other Iranian threat actors such as DarkHydrus and OilRig.