Phantom Mantis, formerly ArmCorp, operates under the "The Gentlemen" partnership program and offers affiliates a support function (LARVA-368) that provides EDR-killing packages tailored to their security stacks during intrusions This article explores phantom mantis armcorp. . The current portfolio includes three chains: G12 and G13, which are automated loaders that decode embedded drivers, register kernel services, and continuously scan for a fixed list of approximately 180 security and management processes from vendors such as Microsoft, CrowdStrike, SentinelOne, Elastic, Sophos, Bitdefender, Kaspersky, ESET, and multiple RMM/VA tools.

When a new kernel image is loaded, G13 evaluates it against a whitelist, CRC32 blacklist, optional byte signatures, and VMProtect markers; on a match, it patches the driver’s entry point to immediately return STATUS_ACCESS_DENIED, effectively preventing defensive drivers from starting, as catalyst explained.

Beyond process termination, G13 introduces destructive memory operations that attach to a selected process, identify writable user-space regions, and overwrite them with repeated patterns (for example 0xCC), aiming to break execution even when termination is blocked or monitored.