{
  "family": "fantom",
  "sample_count": 1,
  "category": "ransomware",
  "description": "<h3>Executive Summary</h3>\nFantom is a highly deceptive Ransomware family that utilizes social engineering at the operating system level. It is designed to extort financial payment from victims by encrypting their critical data while masquerading as a legitimate, critical Windows Update. This visual deception keeps the user unaware of the ongoing encryption process until it is too late.\n\n<h3>Infection Vector and Technical Capabilities</h3>\nFantom is primarily distributed through deceptive software downloads, fake software updates on untrustworthy websites, or via malspam campaigns containing disguised executables.\n\nUpon execution, Fantom initiates a highly deceptive and destructive attack sequence:\n<ul>\n<li><strong>The Fake Windows Update Overlay:</strong> When executed, Fantom immediately displays a full-screen overlay that perfectly mimics the legitimate \"Configuring critical Windows Updates\" screen (complete with a progress counter). This screen blocks access to the desktop, preventing the user from interrupting the process.</li>\n<li><strong>Background Encryption:</strong> While the fake update screen is displayed, the ransomware silently scans all local drives and network shares in the background, encrypting documents, images, and databases using strong cryptography (AES-128/RSA). It typically appends the `.fantom` extension to encrypted files.</li>\n<li><strong>Volume Shadow Copy Deletion:</strong> It executes commands (`vssadmin.exe`) to destroy local system backups and recovery points, ensuring the victim cannot easily restore their files.</li>\n<li><strong>Ransom Note Generation:</strong> Once encryption is complete, the fake update screen disappears, and the desktop wallpaper is replaced with a ransom note instructing the victim to contact an email address for payment instructions.</li>\n</ul>\n\n<h3>Threat Assessment</h3>\nA Fantom infection is a critical security incident resulting in immediate loss of data availability. The deceptive \"Windows Update\" overlay is highly effective against non-technical users, ensuring the encryption process completes uninterrupted. The destruction of local backups means organizations face massive data loss without offline contingencies.\n\n<h3>Incident Response and Remediation</h3>\n<ul>\n<li><strong>Immediate Network Severance:</strong> If the fake update screen is observed, physically disconnect the endpoint from the network and power it down immediately to halt the encryption process (at the risk of corrupting files currently being written).</li>\n<li><strong>Do Not Pay the Ransom:</strong> Paying the ransom is strongly discouraged and does not guarantee data recovery.</li>\n<li><strong>Eradication and Restoration:</strong> The only reliable remediation strategy is a complete bare-metal wipe of the infected systems and a full restoration from secure, air-gapped backups.</li>\n</ul>",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [
    "Ransom.Fantom",
    "Trojan-Ransom.Win32.Fantom",
    "Win32/Filecoder.Fantom"
  ],
  "enrichment_level": "insufficient_information",
  "faq": [],
  "faq_count": 0,
  "mitre_attack": [
    "T1486",
    "T1490",
    "T1036.003"
  ],
  "cisa_advisory": null,
  "last_updated": "2026-07-02T07:03:23Z",
  "type": "Ransomware / Scareware",
  "target_industries": [
    "Global / Opportunistic"
  ],
  "motivation": "Opportunistic",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}