Skip to main content
Skip to main content
Microsoft Security Intelligence
Published Nov 19, 2017 | Updated Nov 08, 2023

TrojanDropper:Win32/PhantomStar.A!dha

Detected by Microsoft Defender Antivirus

Aliases: Alphanc (Symantec)

Summary

TrojanDropper:Win32/PhantomStar.A!dha is the detection for the self-extracting RAR file which is placed on the target device and launches Trojan:Win32/PhantomStar.A!dha or Trojan:Win32/Autophyte.A!dha. This malware has been linked with Diamond Sleet and is used to gain initial access to a target's network.

  • Remove the affected system from the network
  • Thoroughly investigate for other infections in the network
Follow us