PhantomCore is a politically and financially motivated cyberespionage group active since 2022, notably intensifying its activities following the Russo-Ukrainian conflict. The group is also known by aliases such as Fairy Trickster, Head Mare, Rainbow Hyena, and UNG0901. While some reporting links the name 'PhantomCore' to a malware family used by the Head Mare group, authoritative sources also identify PhantomCore as a distinct threat actor group, and the group's operations are consistently described as those of a cyberespionage entity. Its primary motivation involves gaining access to confidential information and disrupting target networks, often deploying ransomware. A defining characteristic is its dual nature, operating as a pro-Ukrainian hacktivist entity while also exhibiting financial motivations through ransomware deployment.