EXECUTIVE SUMMARY
Phantom Mantis is behind the attack, using a type of threat known as a kernel-assisted tool to disable antivirus and other security products before deploying ransomware. The targeted sectors and regions are not specified, but the goal of the attacker is data theft, ransom, or disruption. The threat is significant due to its ability to evade detection and remove defensive controls.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
Phantom Mantis is behind the attack, using a type of threat known as a kernel-assisted tool to disable antivirus and other security products before deploying ransomware. The targeted sectors and regions are not specified, but the goal of the attacker is data theft, ransom, or disruption. The threat is significant due to its ability to evade detection and remove defensive controls.[emaillocker id="1283"]
The malware infects systems through a delivery vector that involves decoding embedded drivers and creating kernel services. Once inside, it scans for targeted security-product processes and submits their IDs to the kernel mode for termination. The attacker maintains control through a device-control interface, allowing for privileged actions such as process termination and kernel interference.
The malware also has the ability to inspect newly loaded drivers, evaluate rules, and patch driver entry points. This threat is significant for organisations due to its ability to evade detection and remove defensive controls, making it difficult to detect or recover from. To defend against this threat, organisations should take defensive actions such as patching, monitoring, backups, and endpoint protection. The ability of the malware to automate target discovery and carry out multiple forms of interference makes it a formidable threat, and organisations should prioritise the sequence of driver-file creation, kernel-service installation, driver load, and security-agent termination to mitigate its impact.
THREAT PROFILE:
| Tactic | Technique ID | Technique | Sub-technique |
| Execution | T1106 | Native API | — |
| Persistence | T1543.003 | Create or Modify System Process | Windows Service |
| Defense Evasion | T1562.001 | Impair Defenses | Disable or Modify Tools |
| Defense Evasion | T1027.005 | Obfuscated Files or Information | Indicator Removal from Tools |
| Discovery | T1057 | Process Discovery | — |
| Discovery | T1082 | System Information Discovery | — |
| Discovery | T1012 | Query Registry | — |
REFERENCES:
The reports contain further technical details:
https://catalyst.prodaft.com/public/report/the-mantis-grip-endpoint-defenses-pinned-before-encryption/overview/yq54e011
https://cybersecuritynews.com/gentlemen-ransomware-kills-security-processes/