Malwarebox public intelligence surface
IIM Feeds for adversary infrastructure chains.
Published IIM chains from MANTIS, shaped for humans first: browse actor infrastructure, compare role flows, open evidence, and export the canonical JSON when you need the raw model.
IIM Atlas Board
Role matrix of the published feed
| chain | actor | conf | entry | redirector | staging | payload | c2 | edges | published |
|---|---|---|---|---|---|---|---|---|---|
withsecure.2026.greyvibe-phantommail-teasoup-phantomrelayv2
GREYVIBE PhantomMail: Ukrainian spear-phishing RAR to TEASOUP JS loader and PhantomRelayV2 C2 pool
|
GREYVIBE | likely | 1 office.cip.ua.gov@gmail.com / offic... | 1 Google Drive-hosted malicious RAR a... | 3 bd3f35b91bf83427e953d4cf531a0ee4b5e... | 2 PhantomRelayV2 watchdog / RzUpdateM... | 6 nycpartnersenterprise.com | 13e / 13r | 2026-05-31 19:17:43 |
Technique pressure
top observed IIM techniquesActor surface
published chain attributionwithsecure.2026.greyvibe-phantommail-teasoup-phantomrelayv2
GREYVIBE PhantomMail: Ukrainian spear-phishing RAR to TEASOUP JS loader and PhantomRelayV2 C2 pool
WithSecure-attributed GREYVIBE PhantomMail lane. April 2026 spear-phishing likely impersonated Ukraine’s State Service of Special Communications and Information Protection, delivered Google Drive-hosted RAR archives, ran TEASOUP-obfuscated JavaScript loaders, and initiated PhantomRelayV2. Confirmed PhantomRelayV2 artifacts and C2 domains are taken from the original WithSecureLabs IOC repository. Exact URL/hash/C2 pairings that are not published are marked likely.