RST TI Report Digest: 20 Apr 2026
ID: b3e886a8-b3ce-5692-ac29-be2ef2594f7e
STIX ID: report--b3e886a8-b3ce-5692-ac29-be2ef2594f7e
Feed Name: RST Cloud Blog
**PhantomCore active campaign and KermitRAT:** PhantomCore, active since 2022, has expanded its toolkit with a proprietary RAT called KermitRAT and uses phishing (malicious HTA files disguised as PDFs), registry changes for persistence, MeshAgent/meshcentral infrastructure, and integrations with tools like CyberStrikeAI and Sliver; the report documents a specific April 8, 2026 attack and provides numerous IoCs (IPs, domains, URLs, file hashes, and an email) for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
