Skip to content
skopnix
← adversaries
Unknown

PhantomControl

misp-galaxyrefreshed 2026-09-15

sigil

Analyst brief

PhantomControl is a sophisticated threat actor that emerged in November 2023. They utilize phishing emails as their initial infection vector and employ a ScreenConnect client to establish a connection for their malicious activities. Their arsenal includes a VBS script that hides its true intentions and reveals a complex mechanism involving PowerShell scripts and image-based data retrieval. PhantomControl has been associated with the Blind Eagle threat actors, showcasing their versatility and reach.

Take it with you
References
Early access

Track PhantomControl on the wire.

Early access opens the actor API and MCP server first — and an alert every time this adversary lands on the wire. One email when it's ready.

bot-protected