logo

Abusing Trusted Business Workflows: A Multi-Stage Phantom Stealer Campaign

ID: 34513f79-d8bc-5e3f-bce7-8b520b900c12

STIX ID: report--34513f79-d8bc-5e3f-bce7-8b520b900c12

Feed Name: Seqrite Blog

Threat Score
75/100

Date Published: 2026-07-22

Date Updated: 2026-07-22

Author: Prashil Moon

...
...

This report describes a multi-stage phishing campaign that delivers Phantom Stealer v3.5.0 using obfuscated JavaScript in compressed attachments which decodes and launches layered PowerShell loaders that ultimately reflectively load a .NET injector and execute a PE in memory; the stealer harvests browser credentials, cookies, wallets and other sensitive data and exfiltrates it via authenticated SMTP (STARTTLS) over port 587. The analysis includes infection chain details, IOCs, detection coverage, and MITRE ATT&CK mappings, and highlights defensive recommendations such as strengthening email security, restricting script execution, and monitoring for PowerShell and unusual SMTP traffic.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.