Another PhantomRAT, But This Time It’s a Previously Undocumented Stealer+RAT
ID: fc2303b5-ed4e-5cf1-9732-7f474c08a1bb
STIX ID: report--fc2303b5-ed4e-5cf1-9732-7f474c08a1bb
Feed Name: Zynap Blog
This report analyzes a sophisticated dropper (prefixed as rundll32.exe, SHA-256 provided) that contains a 56+ MB encrypted overlay decrypted with AES-256-CBC and decompressed to reveal a .NET 10 self-contained bundle carrying PHANTOMRAT. The RAT is a modular stealer and remote-access tool with extensive evasion (AMSI/ETW patching, ntdll unhooking, direct syscalls, anti-VM/sandbox), persistence (Run key, scheduled task, WMI, fileless registry), and capabilities for browser credential and crypto wallet theft, clipboard hijacking, HVNC/remote desktop, reverse proxy, keylogging and wide exfiltration via Discord webhooks with Catbox fallback; the package includes a builder to generate fresh droppers and embedded YARA and IOCs for detection, while the author notes the sample appears to be a development/test build with limited observed circulation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
