logo

Chasing Phantoms: How a Multi-Stage Stealer Abuses…

ID: 257e62cd-dcdb-5df7-9148-834ddec1041f

STIX ID: report--257e62cd-dcdb-5df7-9148-834ddec1041f

Feed Name: Binary Defense Blog

Threat Score
72/100

Date Published: 2026-04-14

Date Updated: 2026-04-27

...
...

Phantom Stealer is a multi-stage information-stealer that leverages process hollowing and legitimate Microsoft-signed binaries (msedge.exe, cookie_exporter.exe) to blend malicious activity into normal system behavior, harvest browser credentials, crypto wallets, Discord tokens, Credential Manager data, and keystrokes, and exfiltrate stolen data via Telegram, Discord webhooks, or FTP; the report outlines the infection chain, persistence via scheduled tasks named under “Updates”, detection opportunities across endpoint and network telemetry, and recommended threat-hunting indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.