logo

Another PhantomRAT, But This Time It’s a Previously Undocumented Stealer+RAT

ID: fc2303b5-ed4e-5cf1-9732-7f474c08a1bb

STIX ID: report--fc2303b5-ed4e-5cf1-9732-7f474c08a1bb

Feed Name: Zynap Blog

Threat Score
72/100

Date Published: 2026-08-05

Date Updated: 2026-08-06

Author: Óscar Gallego Sendín

...
...

This report analyzes a sophisticated dropper (prefixed as rundll32.exe, SHA-256 provided) that contains a 56+ MB encrypted overlay decrypted with AES-256-CBC and decompressed to reveal a .NET 10 self-contained bundle carrying PHANTOMRAT. The RAT is a modular stealer and remote-access tool with extensive evasion (AMSI/ETW patching, ntdll unhooking, direct syscalls, anti-VM/sandbox), persistence (Run key, scheduled task, WMI, fileless registry), and capabilities for browser credential and crypto wallet theft, clipboard hijacking, HVNC/remote desktop, reverse proxy, keylogging and wide exfiltration via Discord webhooks with Catbox fallback; the package includes a builder to generate fresh droppers and embedded YARA and IOCs for detection, while the author notes the sample appears to be a development/test build with limited observed circulation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.