logo

RST TI Report Digest: 20 Apr 2026

ID: b3e886a8-b3ce-5692-ac29-be2ef2594f7e

STIX ID: report--b3e886a8-b3ce-5692-ac29-be2ef2594f7e

Feed Name: RST Cloud Blog

Threat Score
75/100

Date Published: 2026-04-20

Date Updated: 2026-04-29

Author: RST Cloud

...
...

**PhantomCore active campaign and KermitRAT:** PhantomCore, active since 2022, has expanded its toolkit with a proprietary RAT called KermitRAT and uses phishing (malicious HTA files disguised as PDFs), registry changes for persistence, MeshAgent/meshcentral infrastructure, and integrations with tools like CyberStrikeAI and Sliver; the report documents a specific April 8, 2026 attack and provides numerous IoCs (IPs, domains, URLs, file hashes, and an email) for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.