TI Mindmap HUB
Threat Intelligence Report

The Mantis Grip: Endpoint Defenses Pinned Before Encryption

📅 August 2, 2026 📰 catalyst.prodaft.com 🔍 1 CVE(s) referenced

Phantom Mantis combines custom-developed and publicly sourced kernel-mode tools to systematically disable endpoint security controls—including antivirus, EDR, and monitoring agents—before deploying ransomware, using both automated multifunction drivers and BYOVD techniques to ensure rapid, persistent, and flexible defense evasion.

unclassified
CVE-2017-17472

Sign in to access the full report including:
detailed analysis, IOCs, MITRE ATT&CK mapping, and STIX bundle.

🔐 Sign In to Read Full Report

You'll need to accept our Terms of Service to access the platform.

📊 Visual Mindmap
🎯 IOC Extraction
⚔️ MITRE ATT&CK TTPs
📦 STIX 2.1 Bundle