Threat Advisory

Phantom Mantis Group Exploits Security Products

Threat: Malware
Threat Actor Name: Phantom Mantis
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Phantom Mantis is behind the attack, using a type of threat known as a kernel-assisted tool to disable antivirus and other security products before deploying ransomware. The targeted sectors and regions are not specified, but the goal of the attacker is data theft, ransom, or disruption. The threat is significant due to its ability to evade detection and remove defensive controls.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Phantom Mantis is behind the attack, using a type of threat known as a kernel-assisted tool to disable antivirus and other security products before deploying ransomware. The targeted sectors and regions are not specified, but the goal of the attacker is data theft, ransom, or disruption. The threat is significant due to its ability to evade detection and remove defensive controls.[emaillocker id="1283"]

The malware infects systems through a delivery vector that involves decoding embedded drivers and creating kernel services. Once inside, it scans for targeted security-product processes and submits their IDs to the kernel mode for termination. The attacker maintains control through a device-control interface, allowing for privileged actions such as process termination and kernel interference.

The malware also has the ability to inspect newly loaded drivers, evaluate rules, and patch driver entry points. This threat is significant for organisations due to its ability to evade detection and remove defensive controls, making it difficult to detect or recover from. To defend against this threat, organisations should take defensive actions such as patching, monitoring, backups, and endpoint protection. The ability of the malware to automate target discovery and carry out multiple forms of interference makes it a formidable threat, and organisations should prioritise the sequence of driver-file creation, kernel-service installation, driver load, and security-agent termination to mitigate its impact.

THREAT PROFILE:

Tactic Technique ID Technique Sub-technique
Execution T1106 Native API
Persistence T1543.003 Create or Modify System Process Windows Service
Defense Evasion T1562.001 Impair Defenses Disable or Modify Tools
Defense Evasion T1027.005 Obfuscated Files or Information Indicator Removal from Tools
Discovery T1057 Process Discovery
Discovery T1082 System Information Discovery
Discovery T1012 Query Registry

REFERENCES:

The reports contain further technical details:
https://catalyst.prodaft.com/public/report/the-mantis-grip-endpoint-defenses-pinned-before-encryption/overview/yq54e011
https://cybersecuritynews.com/gentlemen-ransomware-kills-security-processes/

[/emaillocker]
crossmenu