Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Phantom Security Group

Phantom Security Group Vendor Cyber Rating & Cyber Score

phantomsec.tools

Phantom Security Group is a current active duty and woman owned offensive cybersecurity firm dedicated to providing comprehensive solutions to our customers. Our team brings years of offensive security experience to the table, are credentialed by multiple institutions, and have work experience at top companies and government organizations in security. We currently offer EvadeX, our Evasion-as-a-Service platform, while we are developing the next stages in offensive capabilities development to automate initial access and post exploitation.


PSG A.I CyberSecurity Scoring

PSG
Company Information
Website:https://phantomsec.tools/
Employees number:5
Number of followers:1,839
NAICS:541514
Industry Type:Computer and Network Security
Homepage:phantomsec.tools
PSG Risk Score (AI oriented)
Between 700 and 749
logo
PSGComputer and Network Security
Updated:
08/06/2026
715/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
PSG Global Score (TPRM)
xxxx
logo
PSGComputer and Network Security
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

PSG
PSGModerate
Current Score
715Ba (MODERATE)
01000
2 incidents
-21 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
717Before Incident
JULY 2026
716Before Incident
JUNE 2026
715Before Incident
MAY 2026
715Before Incident
APRIL 2026
734Before Incident
Cyber Attack
01 Apr 2026PSG
GitLab, Proofpoint, Google, GitHub, Phantom and Firefox: North Korean Hackers Use Fake Coding Tasks to Steal Crypto

North Korean Threat Actor Targets Developers in Large-Scale Phishing Campaign

713After Incident
LOW-21
MOZPHAGITPROGOOGIT1780935989
North Korean Threat Actor Targets Developers in Large-Scale Phishing Campaign A likely North Korean threat actor has conducted a sophisticated phishing campaign, targeting nearly 100 organizations primarily in the U.S. with fake job offers and code-review requests to steal cryptocurrency and credentials. The operation, tracked by Proofpoint as UNK_DeadDrop, sent over 250 malicious emails in April and May 2026, focusing on employees in technology, education, finance, and cryptocurrency firms. ### How the Attack Worked The campaign used shifting pretexts including fake full-stack developer roles, AI payment agent projects, and ERC-4626 smart-contract testing to lure victims into cloning malicious GitHub or GitLab repositories. Once opened in VS Code or Cursor, a hidden tasks.json file executed automatically, exploiting a legitimate editor feature. - VS Code displayed a trust prompt, but Cursor ran the payload silently without user interaction. - The malware installed a fake Google-themed VS Code extension, ensuring persistence by relaunching on macOS and Linux whenever the editor reopened. - Linux/macOS systems received a Go-based remote access trojan (RAT) from the open-source Overlord framework, while Windows ran JavaScript directly in the editor, leaving no disk footprint. ### Data Theft & Wallet Drainage The malware targeted cryptocurrency wallets and browser credentials, including: - Browser extensions: MetaMask, Phantom, Keplr - Desktop wallets: Exodus, Electrum, Ledger Live - Saved passwords & cookies from Chrome, Brave, Edge, and Firefox To bypass security: - macOS/Linux displayed a fake password prompt, using the input to escalate privileges and dump keychains. - Windows bypassed Chrome’s app-bound encryption to extract data. After exfiltration, the malware deleted itself to evade detection. ### Attribution & Distinct Tactics While resembling Contagious Interview a long-running North Korean operation Proofpoint tracks UNK_DeadDrop separately due to its email-led delivery, large-scale repository creation, and self-contained payloads that persist even after infrastructure takedowns. Though attribution remains unconfirmed, the campaign aligns with North Korea’s history of targeting developers since 2022.
INCIDENT DETAILS -
TYPE
Phishing, Malware, Credential Theft, Cryptocurrency Theft
MOTIVATION
Financial gain (cryptocurrency theft), credential theft
IMPACT
Financial Loss: Cryptocurrency wallet drainageData Compromised: Browser credentials, cryptocurrency wallet data, saved passwords, cookiesSystems Affected: macOS, Linux, Windows systems running VS Code or CursorIdentity Theft Risk: High (PII and credentials stolen)Payment Information Risk: High (cryptocurrency wallets targeted)
DATA BREACH
Browser credentialsCryptocurrency wallet dataSaved passwordsCookiesSensitivity Of Data: High (PII, financial data)Personally Identifiable Information: Browser credentials, saved passwords
MARCH 2026
734Before Incident
FEBRUARY 2026
733Before Incident
JANUARY 2026
733Before Incident
DECEMBER 2025
732Before Incident
NOVEMBER 2025
732Before Incident
OCTOBER 2025
731Before Incident
SEPTEMBER 2025
731Before Incident
AUGUST 2024
748Before Incident
Cyber Attack
01 Aug 2024PSG
Phantom Security

Phantom Security Smishing Campaign

720After Incident
HIGH-28
PHA001081124
Phantom Security faced a sophisticated smishing campaign where scammers, identified as a Chinese-language group, targeted users with fake USPS parcel delivery messages to obtain credit card details. Over 438,669 unique credit cards were compromised, with victims spanning across the United States. The scam affected individual finances and potentially damaged the reputation of entities whose emails were associated with the scam, including universities and military or government bodies. The company's red team engineer, Grant Smith, managed to infiltrate and expose the operation, mitigating further damage by assisting USPS investigators and banks in protecting consumers from fraudulent activities.
INCIDENT DETAILS -
TYPE
Smishing Campaign
MOTIVATION
Financial Gain
IMPACT
Data Compromised: Credit card detailsUniversitiesMilitary or government bodiesPayment Information Risk: High
DATA BREACH
Type Of Data Compromised: Credit card detailsNumber Of Records Exposed: 438,669Sensitivity Of Data: High

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for PSG ?
?
What was PSG's A.I Rankiteo Cyber Score in July 2026 ?
?
What was PSG's A.I Rankiteo Cyber Score in June 2026 ?
?
What was PSG's A.I Rankiteo Cyber Score in May 2026 ?
?
What was PSG's A.I Rankiteo Cyber Score in April 2026 ?
?
What was PSG's A.I Rankiteo Cyber Score in March 2026 ?
?
What was PSG's A.I Rankiteo Cyber Score in February 2026 ?
?
What was PSG's A.I Rankiteo Cyber Score in January 2026 ?
?
What was PSG's A.I Rankiteo Cyber Score in December 2025 ?
?
What was PSG's A.I Rankiteo Cyber Score in November 2025 ?
?
What was PSG's A.I Rankiteo Cyber Score in October 2025 ?
?
What was PSG's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on PSG's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with PSG ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view PSG's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?