Phantom Stealer Attacking Users to Steal Sensitive Data like Passwords, Browser Cookies, Credit Card Data
ID: 33804c0f-2f99-5d8d-9418-66b330ef767a
STIX ID: report--33804c0f-2f99-5d8d-9418-66b330ef767a
Feed Name: cybersecurityNews.com
Phantom Stealer v3.5 is a sophisticated info-stealer disguised as Adobe installers that uses obfuscated XML/JavaScript to deploy a PowerShell stage, RC4-encrypted payloads and an in-memory .NET assembly; it injects into Aspnetcompiler.exe via a BLACKHAWK.dll injector, employs Heavens Gate and sandbox/VM checks, harvests browser credentials, crypto wallets, Outlook data, keylogged input and frequent screenshots, and exfiltrates via SMTP/FTP and messaging platforms — organizations should enforce application whitelisting, verify digital signatures, maintain patching and advanced endpoint protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
