ThreatCluster

PHANTOMPULSE RAT Targets Windows Systems with UAC Bypass and Process Injection

First seen 2 Jun 2026, 09:23 UTC GbhackersCybersecuritynews 88% similarity 65

Article Content

Browse articles
ThreatCluster

The PHANTOMPULSE remote access trojan (RAT) has emerged as a significant threat, leveraging UAC bypass and process injection techniques to compromise Windows systems. It is the final payload in a multi-stage attack chain known as REF6598, primarily targeting the cryptocurrency sector. This malware showcases advanced post-exploitation capabilities, making it particularly dangerous for organizations in this space. The attack is characterized by its stealth techniques, which help it evade detection. Security professionals are urged to remain vigilant as the threat landscape evolves. Current mitigation strategies are still being developed as the malware is actively analyzed.

Key Points: • PHANTOMPULSE RAT uses UAC bypass and process injection to compromise Windows systems. • It is linked to a broader attack chain known as REF6598, targeting the cryptocurrency sector. • The malware employs advanced stealth techniques, raising concerns among cybersecurity professionals.

ThreatCluster AI

Timeline

2026-06-02
PHANTOMPULSE RAT identified
Security researchers disclosed the PHANTOMPULSE RAT, highlighting its advanced capabilities and targeting methods.
Gbhackers
2026-06-02
Attack chain REF6598 linked to PHANTOMPULSE
The malware was identified as the final payload in a multi-stage attack chain targeting cryptocurrency systems.
Cybersecuritynews

Community

Browse all →

Tracked Entities in This Story