#threatreport #MediumCompleteness
Restless spirit: PhantomCore spies have carried out new attacks on Russian companies | 22-01-2026
Source:
habr.com/ru/companies/F6/art…
Key details below ↓
🧑💻Actors/Campaigns:
Phantomcore
💀Threats:
Phantomcore, Phantomeremote,
🎯Victims: Housing and utilities, Finance, Urban infrastructure and municipal services, Aerospace, Consumer digital services, Chemical industry, Construction, Consumer goods, Electronic commerce, Marketplaces, ...
🏭Industry: E-commerce, Financial, Aerospace, Chemical
🌐Geo: Belarusian, Russian
🧨IOCs:
- Command: 2
- File: 2
- Domain: 7
- Path: 1
- IP: 4
- Hash: 10
💽Software: Windows Task Scheduler
🔢Algorithms: sha1
⚙️Win Services: WebClient
📜Programming Languages: powershell
#threatreport:
PhantomCore, a cyber espionage group, has recently targeted multiple sectors within Russian companies, utilizing malicious email campaigns to execute their attacks. Analysts from the F6 Cybersecurity Center reported that these attacks were launched on January 19 and 21, 2026, with emails directed towards various industries, including housing and utilities, finance, urban infrastructure, municipal services, aerospace, B2C digital services, chemical production, construction, consumer goods, and e-commerce.
The F6 Business Email Protection (BEP) system played a crucial role in identifying and blocking these malicious communications before they reached their intended targets. The content of these emails likely aimed to facilitate unauthorized access to sensitive information or exploit specific vulnerabilities in the targeted organizations.
Although specific details regarding the malware used or the techniques employed by PhantomCore were not disclosed, the targeting of diverse sectors suggests a strategic approach aimed at gathering intelligence or sabotaging operations within critical industries. This reflects the group's ongoing commitment to cyber espionage activities within Russia, highlighting the persistent threat posed by advanced persistent threats (APTs) like PhantomCore.
The focus on various types of services and industries indicates an adaptive attack strategy that could leverage different attack vectors tailored to the environment and infrastructure of each sector, ultimately enhancing the group’s chances of achieving its malicious objectives.