Operation MoneyMount-ISO — Deploying Phantom Stealer via ISO-Mounted Executables
ID: 25277e00-33af-5707-ad46-2af888aef11d
STIX ID: report--25277e00-33af-5707-ad46-2af888aef11d
Feed Name: Seqrite Blog
Executive Summary: Seqrite Labs detected a Russian-language phishing campaign targeting finance and related roles that distributes Phantom stealer through a ZIP attachment containing a malicious ISO which auto-mounts and executes a staged payload chain. The analysis documents payload delivery (ZIP→ISO→exe→DLL→in-memory Phantom), anti-analysis techniques, extensive data-harvesting modules (browser passwords, cookies, Discord tokens, crypto wallets, keylogger, clipboard monitor, file grabber), multiple exfiltration channels (Telegram, Discord webhooks, FTP), IOCs, and MITRE ATT&CK mappings, and recommends hardened mail/workflow controls and container/behavioral defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
