Phantom Goblin: Covert Credential Theft Analysis
ID: 4e927d0c-b20b-5cae-8629-f8eeb26b0f5c
STIX ID: report--4e927d0c-b20b-5cae-8629-f8eeb26b0f5c
Feed Name: Cyble Blog
Phantom Goblin is a covert credential‑theft campaign distributing malicious LNK files inside RAR attachments that execute PowerShell to download Go‑based binaries from GitHub. The payloads terminate browsers to extract cookies and credentials (bypassing App Bound Encryption via remote debugging), collect broad browser data, create VSCode tunnels for persistent remote access, persist via HKCU Run registry entries, and exfiltrate archives and tunnel details to a Telegram bot; the report includes SHA‑256 IOCs, download URLs, MITRE ATT&CK mappings, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
