Phantom Stealer Campaign Uses JavaScript and PowerShell to Steal Browser Credentials
ID: 7c8528a2-e5a7-553e-a026-3e2f7925b8eb
STIX ID: report--7c8528a2-e5a7-553e-a026-3e2f7925b8eb
Feed Name: GBHackers
Seqrite documents a targeted phishing campaign that delivers Phantom Stealer v3.5.0 via business-themed emails (UPS and Malaysian tax notices) containing malicious JavaScript archives. The staged infection uses obfuscated JS to drop Base64-encoded PowerShell, AES/XOR-encrypted payloads, and a .NET injector that reflectively loads the stealer into aspnet_compiler.exe for in-memory execution. Phantom Stealer harvests browser credentials, cookies, payment data, messaging app data, and cryptocurrency wallets, then exfiltrates via SMTP (STARTTLS), and the report provides hashes, detections, and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
