logo

Phantom Stealer: Credential Theft as a Service

ID: 5861f7d3-17a9-5098-ac78-2f9634fa01df

STIX ID: report--5861f7d3-17a9-5098-ac78-2f9634fa01df

Feed Name: Group-IB Blog

Threat Score
70/100

Date Published: 2026-03-31

Date Updated: 2026-06-04

...
...

Group-IB observed and blocked a multi-wave phishing campaign (Nov 2025–Jan 2026) delivering Phantom Stealer — a commercial .NET infostealer — to European logistics, manufacturing, and technology firms; attackers used procurement-themed, spoofed emails with archived droppers, and the report includes IOCs (domain and several IPs) and detection details from Group-IB’s Business Email Protection and Malware Detonation Platform.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.