logo

Operation MoneyMount-ISO — Deploying Phantom Stealer via ISO-Mounted Executables

ID: 25277e00-33af-5707-ad46-2af888aef11d

STIX ID: report--25277e00-33af-5707-ad46-2af888aef11d

Feed Name: Seqrite Blog

Threat Score
75/100

Date Published: 2025-12-12

Date Updated: 2026-04-30

Author: Dixit Panchal

...
...

Executive Summary: Seqrite Labs detected a Russian-language phishing campaign targeting finance and related roles that distributes Phantom stealer through a ZIP attachment containing a malicious ISO which auto-mounts and executes a staged payload chain. The analysis documents payload delivery (ZIP→ISO→exe→DLL→in-memory Phantom), anti-analysis techniques, extensive data-harvesting modules (browser passwords, cookies, Discord tokens, crypto wallets, keylogger, clipboard monitor, file grabber), multiple exfiltration channels (Telegram, Discord webhooks, FTP), IOCs, and MITRE ATT&CK mappings, and recommends hardened mail/workflow controls and container/behavioral defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.