New Phantom Stealer Campaign Hits Windows Machines Through ISO Mounting
ID: 2662c1e5-8561-5295-bbce-c358e689b670
STIX ID: report--2662c1e5-8561-5295-bbce-c358e689b670
Feed Name: cybersecurityNews.com
Operation MoneyMount-ISO is a phishing campaign delivering Phantom Stealer via ZIP/ISO attachments impersonating bank transfer confirmations to target finance and related departments in Russia. The malware auto-mounts ISO payloads, injects a DLL that decrypts and runs the stealer, and exfiltrates harvested data — including browser-saved credentials, crypto wallet data, Discord tokens, clipboard contents, and keystrokes — via Telegram, Discord webhooks, and FTP; the report includes IOCs and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
