Signed & Stolen: “Phantom Stealer” Hijacks Java App via Fake DHL Invoice
ID: 5e69681b-67f5-5583-8aa1-094ea185ddb9
STIX ID: report--5e69681b-67f5-5583-8aa1-094ea185ddb9
Feed Name: securityonline.info
A sophisticated multi-stage campaign lures victims with a fake DHL invoice containing a signed Java utility renamed to DHL-INVOICE.exe and a malicious jli.dll; Windows DLL sideloading causes the trusted launcher to load the malicious DLL, which activates an XLoader-style loader that decrypts and injects the final payload via process hollowing into AddInProcess32.exe. The final payload, Phantom Stealer v3.5.0, is a modular .NET information stealer that harvests credentials and exfiltrates data, and the attackers protect their configuration using AES-256-CBC with PBKDF2-derived keys to hinder analysis.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
