Abusing Trusted Business Workflows: A Multi-Stage Phantom Stealer Campaign
ID: 34513f79-d8bc-5e3f-bce7-8b520b900c12
STIX ID: report--34513f79-d8bc-5e3f-bce7-8b520b900c12
Feed Name: Seqrite Blog
This report describes a multi-stage phishing campaign that delivers Phantom Stealer v3.5.0 using obfuscated JavaScript in compressed attachments which decodes and launches layered PowerShell loaders that ultimately reflectively load a .NET injector and execute a PE in memory; the stealer harvests browser credentials, cookies, wallets and other sensitive data and exfiltrates it via authenticated SMTP (STARTTLS) over port 587. The analysis includes infection chain details, IOCs, detection coverage, and MITRE ATT&CK mappings, and highlights defensive recommendations such as strengthening email security, restricting script execution, and monitoring for PowerShell and unusual SMTP traffic.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
