logo

New Phantom Stealer Campaign Hits Windows Machines Through ISO Mounting

ID: 2662c1e5-8561-5295-bbce-c358e689b670

STIX ID: report--2662c1e5-8561-5295-bbce-c358e689b670

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2025-12-13

Date Updated: 2026-04-21

Author: Dhivya

...
...

Operation MoneyMount-ISO is a phishing campaign delivering Phantom Stealer via ZIP/ISO attachments impersonating bank transfer confirmations to target finance and related departments in Russia. The malware auto-mounts ISO payloads, injects a DLL that decrypts and runs the stealer, and exfiltrates harvested data — including browser-saved credentials, crypto wallet data, Discord tokens, clipboard contents, and keystrokes — via Telegram, Discord webhooks, and FTP; the report includes IOCs and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.