Phantom Stealer: Credential Theft as a Service
ID: 5861f7d3-17a9-5098-ac78-2f9634fa01df
STIX ID: report--5861f7d3-17a9-5098-ac78-2f9634fa01df
Feed Name: Group-IB Blog
Threat Score
Group-IB observed and blocked a multi-wave phishing campaign (Nov 2025–Jan 2026) delivering Phantom Stealer — a commercial .NET infostealer — to European logistics, manufacturing, and technology firms; attackers used procurement-themed, spoofed emails with archived droppers, and the report includes IOCs (domain and several IPs) and detection details from Group-IB’s Business Email Protection and Malware Detonation Platform.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
