Tool
PhantomProxyLite
- First Reported
- Apr 15, 2026
- Latest Reported
- Apr 15, 2026
Reported Context (1)
- the campaign deployed a PowerShell backdoor called PhantomHeart alongside a rewritten proxy tool PhantomProxyLite. The malware leveraged AES-encrypted C2 communications, persistence through scheduled tasks, and Hunt.io Maps More Than 1,250 C2 Servers Across 165 Russian Providers
CVE (1)
Malware (14)
Threat Actors (3)
MITRE ATT&CK (10)
Vendors (19)
Products (6)
Tools (10)
Industries (2)
Countries (2)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.