logo

Phantom Stealer Attacking Users to Steal Sensitive Data like Passwords, Browser Cookies, Credit Card Data

ID: 33804c0f-2f99-5d8d-9418-66b330ef767a

STIX ID: report--33804c0f-2f99-5d8d-9418-66b330ef767a

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2025-12-18

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Phantom Stealer v3.5 is a sophisticated info-stealer disguised as Adobe installers that uses obfuscated XML/JavaScript to deploy a PowerShell stage, RC4-encrypted payloads and an in-memory .NET assembly; it injects into Aspnetcompiler.exe via a BLACKHAWK.dll injector, employs Heavens Gate and sandbox/VM checks, harvests browser credentials, crypto wallets, Outlook data, keylogged input and frequent screenshots, and exfiltrates via SMTP/FTP and messaging platforms — organizations should enforce application whitelisting, verify digital signatures, maintain patching and advanced endpoint protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.