Russian Phishing Campaign Delivers Phantom Stealer Via ISO Files
ID: 9e9be0cd-3935-5c25-8544-94ef6177598b
STIX ID: report--9e9be0cd-3935-5c25-8544-94ef6177598b
Feed Name: Infosecurity Magazine (News)
Operation MoneyMount-ISO is an active phishing campaign observed by Seqrite Labs that uses ZIP archives containing auto-mounted ISO files to present disguised executables which deploy Phantom Stealer in memory; the stealer exfiltrates browser passwords, cookies, credit-card data, crypto wallets, keystrokes, clipboard contents and Discord tokens via channels like Telegram bots, Discord webhooks and FTP. The campaign targets Russian-speaking finance, accounting, procurement, HR and executive-assistant roles, employs anti-analysis checks and ISO-based initial access to evade email security, and underscores the need for containerized attachment filtering, memory-behaviour monitoring and hardened finance-facing mail workflows.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
