MalwareBazaar Database

This page shows some basic information the YARA rule MAL_Kernel_RegPhantom_Mar26 including corresponding malware samples.

Database Entry


YARA Rule:MAL_Kernel_RegPhantom_Mar26
Author:Pezier Pierre-Henri (Nextron Systems)
Description:Detects RegPhantom, a kernel-mode rootkit that allow attacker to inject arbitrary code from unprivileged user-mode into kernel-mode and execute it.
Firstseen:2026-10-07 09:34:45 UTC
Lastseen:2026-10-07 09:41:51 UTC
Sightings:19

Malware Samples


The table below shows all malware samples that matching this particular YARA rule (max 1000).

Firstseen (UTC)SHA256 hashTagsSignatureReporter