PhantomGraph is a backdoor that shares code overlap with PhantomCore. It consists of two DLL modules: SysExcSvc.dll for receiving commands and exfiltrating results to Microsoft OneDrive, and SysReadSvc.dll for parsing and executing commands. The malware is installed as Windows services and is designed to evade EDR detection.