logo

RegPhantom Backdoor Threat Analysis

ID: beb12634-eb2d-5f1a-ac36-0c1d6c5b7fd5

STIX ID: report--beb12634-eb2d-5f1a-ac36-0c1d6c5b7fd5

Feed Name: Nextron Systems

Threat Score
80/100

Date Published: 2026-03-20

Date Updated: 2026-04-28

Author: Pierre-Henri Pezier

...
...

**Executive Summary:** RegPhantom is a stealthy, signed Windows kernel rootkit that intercepts registry writes as an XOR-encrypted command channel to reflectively map and execute arbitrary PE payloads in kernel space, then erases traces (blocks writes, wipes memory, encodes hook pointers) to avoid detection; multiple samples and Chinese-issued code-signing certificates indicate active maintenance by a China‑nexus actor at moderate confidence, and defenders should prioritize detection of the driver binary and stable byte-level patterns (YARA) rather than relying on runtime artifacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.