PSG A.I CyberSecurity Scoring
PSG
Company Information
Website:https://phantomsec.tools/
Employees number:5
Number of followers:1,839
NAICS:541514
Industry Type:Computer and Network Security
Homepage:phantomsec.tools
PSG Risk Score (AI oriented)
Between 700 and 749
PSGComputer and Network Security
Updated:
08/06/2026
08/06/2026
715/1000
Moderate
Ba
PSG Global Score (TPRM)
xxxx
PSGComputer and Network Security
Score locked

PSGModerate
Current Score
715Ba (MODERATE)
01000
2 incidents
-21 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
717
JULY 2026
716
JUNE 2026
715
MAY 2026
715
APRIL 2026
734
Cyber Attack
01 Apr 2026 • PSG
GitLab, Proofpoint, Google, GitHub, Phantom and Firefox: North Korean Hackers Use Fake Coding Tasks to Steal Crypto
North Korean Threat Actor Targets Developers in Large-Scale Phishing Campaign
713
LOW-21
MOZPHAGITPROGOOGIT1780935989
North Korean Threat Actor Targets Developers in Large-Scale Phishing Campaign
A likely North Korean threat actor has conducted a sophisticated phishing campaign, targeting nearly 100 organizations primarily in the U.S. with fake job offers and code-review requests to steal cryptocurrency and credentials. The operation, tracked by Proofpoint as UNK_DeadDrop, sent over 250 malicious emails in April and May 2026, focusing on employees in technology, education, finance, and cryptocurrency firms.
### How the Attack Worked
The campaign used shifting pretexts including fake full-stack developer roles, AI payment agent projects, and ERC-4626 smart-contract testing to lure victims into cloning malicious GitHub or GitLab repositories. Once opened in VS Code or Cursor, a hidden tasks.json file executed automatically, exploiting a legitimate editor feature.
- VS Code displayed a trust prompt, but Cursor ran the payload silently without user interaction.
- The malware installed a fake Google-themed VS Code extension, ensuring persistence by relaunching on macOS and Linux whenever the editor reopened.
- Linux/macOS systems received a Go-based remote access trojan (RAT) from the open-source Overlord framework, while Windows ran JavaScript directly in the editor, leaving no disk footprint.
### Data Theft & Wallet Drainage
The malware targeted cryptocurrency wallets and browser credentials, including:
- Browser extensions: MetaMask, Phantom, Keplr
- Desktop wallets: Exodus, Electrum, Ledger Live
- Saved passwords & cookies from Chrome, Brave, Edge, and Firefox
To bypass security:
- macOS/Linux displayed a fake password prompt, using the input to escalate privileges and dump keychains.
- Windows bypassed Chrome’s app-bound encryption to extract data.
After exfiltration, the malware deleted itself to evade detection.
### Attribution & Distinct Tactics
While resembling Contagious Interview a long-running North Korean operation Proofpoint tracks UNK_DeadDrop separately due to its email-led delivery, large-scale repository creation, and self-contained payloads that persist even after infrastructure takedowns. Though attribution remains unconfirmed, the campaign aligns with North Korea’s history of targeting developers since 2022.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
734
FEBRUARY 2026
733
JANUARY 2026
733
DECEMBER 2025
732
NOVEMBER 2025
732
OCTOBER 2025
731
SEPTEMBER 2025
731
AUGUST 2024
748
Cyber Attack
01 Aug 2024 • PSG
Phantom Security
Phantom Security Smishing Campaign
720
HIGH-28
PHA001081124
Phantom Security faced a sophisticated smishing campaign where scammers, identified as a Chinese-language group, targeted users with fake USPS parcel delivery messages to obtain credit card details. Over 438,669 unique credit cards were compromised, with victims spanning across the United States. The scam affected individual finances and potentially damaged the reputation of entities whose emails were associated with the scam, including universities and military or government bodies. The company's red team engineer, Grant Smith, managed to infiltrate and expose the operation, mitigating further damage by assisting USPS investigators and banks in protecting consumers from fraudulent activities.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for PSG ??
What was PSG's A.I Rankiteo Cyber Score in July 2026 ??
What was PSG's A.I Rankiteo Cyber Score in June 2026 ??
What was PSG's A.I Rankiteo Cyber Score in May 2026 ??
What was PSG's A.I Rankiteo Cyber Score in April 2026 ??
What was PSG's A.I Rankiteo Cyber Score in March 2026 ??
What was PSG's A.I Rankiteo Cyber Score in February 2026 ??
What was PSG's A.I Rankiteo Cyber Score in January 2026 ??
What was PSG's A.I Rankiteo Cyber Score in December 2025 ??
What was PSG's A.I Rankiteo Cyber Score in November 2025 ??
What was PSG's A.I Rankiteo Cyber Score in October 2025 ??
What was PSG's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on PSG's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with PSG ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view PSG's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?