logo

Phantom Goblin: Covert Credential Theft Analysis

ID: 4e927d0c-b20b-5cae-8629-f8eeb26b0f5c

STIX ID: report--4e927d0c-b20b-5cae-8629-f8eeb26b0f5c

Feed Name: Cyble Blog

Threat Score
72/100

Date Published: 2025-04-24

Date Updated: 2026-07-16

...
...

Phantom Goblin is a covert credential‑theft campaign distributing malicious LNK files inside RAR attachments that execute PowerShell to download Go‑based binaries from GitHub. The payloads terminate browsers to extract cookies and credentials (bypassing App Bound Encryption via remote debugging), collect broad browser data, create VSCode tunnels for persistent remote access, persist via HKCU Run registry entries, and exfiltrate archives and tunnel details to a Telegram bot; the report includes SHA‑256 IOCs, download URLs, MITRE ATT&CK mappings, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.