logo

Beware of phishing emails disguised as requests to review quotes (PhantomStealer)

ID: d5a94ca8-f65b-5dab-ac97-c03c7ddf50f1

STIX ID: report--d5a94ca8-f65b-5dab-ac97-c03c7ddf50f1

Feed Name: ASEC

Threat Score
75/100

Date Published: 2026-08-11

Date Updated: 2026-08-18

Author: ATCP

...
...

AhnLab ASEC describes a phishing campaign that delivered an injector executable inside a .GZ attachment which uses SSPI/CMSTPLUA and ShellExecuteExW UAC techniques, installs a vulnerable driver (C:\Windows\Temp\DCRCVDrv.Sys / service NvStreamKmd_dcrcv) to invoke kernel IOCTL 0x2205C0 and terminate security processes, performs process hollowing into AddInProcess32.Exe to run PhantomStealer, and exfiltrates credentials, keystrokes, screenshots, cookies, and cryptocurrency wallets while performing clipboard clipping; the report provides file names, service/device indicators, IOCTL and process targets, MD5s, and recommended immediate actions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.