Phantom Project Bundles Infostealer, Crypter and RAT For Sale
ID: ff9c715b-8786-55e7-b4fc-661880bf4de0
STIX ID: report--ff9c715b-8786-55e7-b4fc-661880bf4de0
Feed Name: Infosecurity Magazine (News)
Group-IB detailed Phantom Stealer, a commercial .NET infostealer distributed via a five-wave phishing campaign across European logistics, manufacturing and technology companies between November 2025 and January 2026; the malware harvests browser credentials, cookies, saved passwords, autofill and payment card data, messaging and email session information, and Wi‑Fi credentials, and exfiltrates data via messaging platforms, SMTP and FTP. Phishing emails used procurement-themed lures with archive attachments containing obfuscated JavaScript droppers or malicious executables, and investigators identified consistent indicators such as SPF failures, missing DKIM, reused templates and spelling errors that revealed a coordinated stealer-as-a-service operation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
