Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Phantom Stealer

134
Global rank
90 infographic chevron month
Month rank
93 infographic chevron week
Week rank

Phantom Stealer is a commercially available Malware-as-a-Service infostealer targeting Windows systems. It harvests browser passwords, session cookies, payment data, cryptocurrency wallets, system information, screenshots, and application data.

Stealer
Type
Unknown
Origin
1 October, 2025
First seen
3 October, 2026
Last seen

How to analyze Phantom Stealer with ANY.RUN

Type
Unknown
Origin
1 October, 2025
First seen
3 October, 2026
Last seen

IOCs

IP addresses
185.125.190.56
91.189.91.64
91.189.91.42
185.125.188.54
185.125.190.57
185.125.188.59
185.125.188.55
185.125.188.61
23.52.181.141
2.16.164.82
40.126.31.69
40.84.97.4
48.209.138.189
23.59.18.102
48.209.138.168
48.192.1.65
74.179.77.164
135.233.95.144
23.48.23.62
2.23.246.101
Hashes
4377e894b3e7956b74d467118164b7023e9b0f0f4c151e464d00991e30f924ac
f9120c06aad5aa4add1b646456199fd34b4fa72c6eb8ba4d37d85a59d7cac478
b05c27574c61a7b79ee20aa6e5fa00ddb30027d7063bd587fd468f41845b386b
d8120ef961aa32d03f2623c07a801d07ef7764a2a0da1d9c79678d91fe0b1f7a
d2501059efb3723eafb1bc76f2209a48bdcc9568edfc012d259748fe8a9011f6
ddb9d916b9a350009121972942e22143cc9b2fba3bb4c59652270a27923ee952
3205dbae4886429b1bb97e05c5bb20391393985c44f43f25a96ca2073e207811
c2eb74cb1d60bf0a61eb5691edecb9d9ad9aeecead8e19473b6aaeaca34f7a9b
59304fb2381182726d6217e75de34846479c744335b5584289bcb93299e7ffac
8bbf3733f7e553848faee92c9b102b92036d12e7a881b19371228e099f7501b3
1e382eae677cba4df79f641410c939a079c8014891408aa74a3806f256db623f
2f789476df0453bd659f8260ba4d84b4d63cd6c99b8cd66a2f914b41b353cbe6
9ba8214c7bf978f6cbcffacfcda11e8ce42478f66ffae6f9870800d61efea00c
2bc48c30c3b9342f286180b8d7cef2469889e3514532fc55a55fc7340c320c0c
8eabf7f083838299503a044384b34d8559ccf3a482d2e5655bf62740b75a7b8f
904a6e197defe5d3e166073714ce908329805922c30500c9309388ebce213a99
6ab717fee3f5039394da26fea18f179917e354bb7264f25356b7098b52115323
248139ceac572138a8739083331cb4541ba006aa124db7dff440ba36ede24a38
ca65f101ac14619c2d839d147de2cbf1cf7b4b1a6d2f6e98b955c5b4b31860b8
e5dbea890922da117574620ca8543bc1e8689b9ec3a73e1589594a8ed36e0ed1
Domains
api.snapcraft.io
google.com
connectivity-check.ubuntu.com
dashboard.snapcraft.io
4.100.168.192.in-addr.arpa
canonical-bos01.cdn.snapcraftcontent.com
settings-win.data.microsoft.com
fe3cr.delivery.mp.microsoft.com
slscr.update.microsoft.com
client.wns.windows.com
ocsp.digicert.com
www.microsoft.com
self.events.data.microsoft.com
activation-v2.sls.microsoft.com
nexusrules.officeapps.live.com
crl.microsoft.com
go.microsoft.com
zynimg.com
login.live.com
ecs.office.com
URLs
http://connectivity-check.ubuntu.com/
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/microsoft%20secure%20server%20ca%202026.crl
https://login.live.com/ppsecure/deviceaddcredential.srf
https://activation-v2.sls.microsoft.com/slactivateproduct/slactivateproduct.asmx?configextension=retail
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=0&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?processorclockspeed=3094&flightids=&updateoffereddays=4294967295&branchreadinesslevel=cb&oemmanufacturername=dell&isclouddomainjoined=0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&sku=48&activationchannel=retail&attrdataver=186&ismdmenrolled=0&processorcores=6&processormodel=amd%20ryzen%205%203500%206-core%20processor&totalphysicalram=6144&primarydisktype=4294967295&flightingbranchname=&chassistypeid=1&oemmodelnumber=dell&systemvolumetotalcapacity=260281&sampleid=95271487&deviceclass=windows.desktop&app=muse&disabledualscan=0&appver=10.0&oemsubmodel=j5cr&locale=en-us&isalwaysonalwaysconnectedcapable=0&ms=0&defaultuserregion=244&updateserviceurl=http%3a%2f%2fneverupdatewindows10.com&osver=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&deferqualityupdateperiodindays=0&ring=retail&deferfeatureupdateperiodindays=30
https://slscr.update.microsoft.com/sls/%7b522d76a4-93e1-47f8-b8ce-07c937ad1a1e%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20secure%20server%20ca%202.1.crl
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
https://slscr.update.microsoft.com/sls/ping
https://slscr.update.microsoft.com/sls/%7be7a50285-d08d-499d-9ff8-180fdc2332bc%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
https://settings-win.data.microsoft.com/settings/v3.0/wsd/updatehealthtools?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=s:bad99146-31d3-4ec6-a1a4-be76f32ba5d4&sampleid=s:95271487&appver=10.0.19041.3626&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=sedimentpack&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
http://www.microsoft.com/pkiops/crl/microsoft%20update%20signing%20ca%202.3.crl
http://www.microsoft.com/pkiops/crl/microsoft%20update%20signing%20ca%202.2.crl
http://crl.microsoft.com/pki/crl/products/microoceraut_2010-06-23.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://login.live.com/rst2.srf
Last Seen at

Recent blog posts

post image
Threat Coverage Digest: New Malware Reports a...
watchers 5397
comments 0
post image
Phishing Response Protocol: 3 Essential SOC S...
watchers 7569
comments 0
post image
Major Cyber Attacks in September 2026: US and...
watchers 11530
comments 0

Key Takeaways

  • Credential and Data Theft: Phantom Stealer targets browser passwords, session cookies, payment information, cryptocurrency wallets, and other sensitive data.
  • Windows-Focused Threat: The malware is designed to compromise Windows endpoints and can interact with browsers and applications installed on the victim's system.
  • MaaS Distribution: Phantom Stealer is commercially offered as a Malware-as-a-Service product, allowing multiple threat actors to deploy it in different campaigns.
  • Phishing Delivery: Recent campaigns have used business-themed phishing emails and compressed attachments to deliver the stealer.
  • Evasion-Focused Execution: Variants use obfuscation, PowerShell, process injection, and in-memory execution to reduce the visibility of the payload.
  • Multiple Exfiltration Channels: Stolen information can be sent through channels including Telegram, Discord, SMTP, and FTP.
  • ANY.RUN’s Interactive Sandbox analysis shows Phantom Stealer harvesting browser credentials, session cookies, financial data, and other sensitive information, while using in-memory execution and process injection to evade detection.

What is Phantom Stealer?

Phantom Stealer is a commercially distributed Windows infostealer built to collect valuable information from compromised systems. It targets major web browsers, including Chrome, Firefox, and Edge, harvesting credentials, cookies, payment information, and other browser data.

The malware can also collect cryptocurrency wallet information, screenshots, clipboard contents, keystrokes, system information, and data associated with applications such as Discord, Telegram, and Steam.
Phantom Stealer is offered through a subscription-based Malware-as-a-Service model, lowering the technical barrier for threat actors who want to conduct credential theft and information-stealing campaigns. Recent reporting attributes the operation to an actor using the alias Oldphantomoftheopera and the Phantom Softwares group.

How Phantom Stealer Threatens Businesses and Organizations

A successful Phantom Stealer infection can expose organizations to risks beyond the initial endpoint compromise:

  • Account takeover: Stolen browser passwords and session cookies can provide access to corporate accounts and web applications.
  • Financial loss: Payment information and cryptocurrency wallet data can be targeted for direct financial theft.
  • Credential exposure: Browser-stored credentials can include access to email, SaaS platforms, administrative portals, and other business services.
  • Session hijacking: Stolen cookies and authentication data may allow attackers to reuse existing authenticated sessions.
  • Follow-on attacks: Compromised credentials can provide attackers with additional opportunities for phishing, fraud, and further intrusion.
  • Data exposure: Screenshots, clipboard contents, application data, and system information can reveal additional sensitive information.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Victimology: Who Is Most Vulnerable?

Phantom Stealer can affect organizations across industries because its primary targets — browser credentials, cookies, financial information, and application data — are commonly present on Windows workstations. Recent campaigns have particularly used business-themed phishing lures, including documents and quote-request themes, suggesting targeting of corporate environments.
The MaaS model also means that Phantom Stealer should not be associated with a single victim profile or threat actor. Different operators can deploy the same malware through their own phishing infrastructure and delivery chains.

How Does Phantom Stealer Function?

Observing a Phantom Stealer sample inside ANY.RUN’s Interactive Sandbox reveals a multi-stage infection chain designed to move from phishing delivery to in-memory payload execution and data exfiltration.

The infection chain begins with wscript.exe acting as a launcher and progresses through WMI, hidden PowerShell execution, remote payload retrieval, in-memory loading, and browser targeting.

Phantom Stealer detonated inside ANY.RUN’s Interactive Sandbox Phantom Stealer detonated inside ANY.RUN’s Interactive Sandbox

Stage 1: JavaScript Loader

The infection begins with shim.js, a JavaScript loader executed through wscript.exe. Rather than launching the main payload directly, the script uses WMI to create a hidden PowerShell process.

The observed execution chain is:

JS loader → WMI → PowerShell → remote payload → PE payload

This approach keeps the primary payload separate from the initial JavaScript file and allows the next stages to be retrieved and executed dynamically.

wscript.exe launching the Phantom Stealer JavaScript loader wscript.exe launching the Phantom Stealer JavaScript loader

Stage 2: Hidden PowerShell Execution

The WMI-created PowerShell process runs with several parameters designed to limit visibility and restrictions:

  • -ExecutionPolicy Bypass bypasses the standard PowerShell execution policy.
  • -NoProfile prevents user PowerShell profiles from affecting execution.
  • -WindowStyle Hidden keeps the PowerShell window invisible.

The script then retrieves code from the INTERNAL_DB_CACHE user environment variable and executes it using IEX (Invoke-Expression). Afterward, the variable is deleted, removing the stored value from the user environment.

PowerShell running in hidden mode PowerShell running in hidden mode

Stage 3: Remote Payload Retrieval

The PowerShell stage creates a .NET WebClient and uses DownloadData() to retrieve data from a remote resource over HTTPS.

The downloaded object is presented as a PNG file, allowing the next-stage payload to appear as a legitimate image resource rather than an executable.

PowerShell downloading the second-stage payload via .NET WebClient PowerShell downloading the second-stage payload via .NET WebClient

Stage 4: Payload Decoding

The downloaded bytes are converted into a string and passed through FromBase64String(). The resulting data begins with the MZ signature associated with Windows PE files.

The observed chain is therefore:

HTTPS request → PNG-like data → byte array → Base64 decoding → PE payload

The presence of XICC_PROFILE within the downloaded data further supports the use of image data as a container for the next stage.

PNG file used to deliver the next-stage payload PNG file used to deliver the next-stage payload

Stage 5: In-Memory Loading

Rather than simply writing the decoded executable to disk, the payload is loaded from a byte array using .NET's Load(System.Byte[]). This allows the PE/.NET assembly to be loaded directly into memory, reducing the need for a conventional executable file on disk and making the execution chain harder to detect through file-based analysis alone.

Stage 6: Phantom Process and Browser Targeting

Following the loader activity, AddInProcess32.exe appears in the process tree and is associated with the Phantom payload. The use of a legitimate Windows/.NET component name can make the process appear less suspicious when viewed by name alone.

The process subsequently launches separate instances of:

  • chrome.exe
  • firefox.exe
  • msedge.exe

Each browser is started with its own temporary profile directories. This behavior is consistent with Phantom Stealer's focus on browser environments and provides the malware with access to browser-related authentication and account data.

Overall, the analyzed execution chain combines WMI-based process creation, hidden PowerShell, remote payload retrieval, encoded delivery, in-memory loading, and browser interaction to conceal the stealer and reach its primary data sources.

The Evolution of Phantom Stealer

Phantom Stealer has appeared in multiple variants and delivery chains, with recent campaigns placing significant emphasis on stealth and in-memory execution.

  • Commercial distribution: Phantom Stealer is offered through a MaaS model, allowing different operators to deploy the malware.
  • Multi-stage delivery: Campaigns use layered scripts, loaders, and decoding mechanisms to conceal the final payload.
  • Improved evasion: Recent activity has incorporated process injection and in-memory execution to reduce traditional file-based detection opportunities.
  • Expanded targeting: The malware targets not only browser credentials but also cryptocurrency wallets, financial data, messaging applications, screenshots, and clipboard contents.
  • Flexible exfiltration: Operators can use multiple communication channels to retrieve stolen information.

How Businesses Can Use ANY.RUN’s Threat Intelligence Against Phantom Stealer

Phantom Stealer uses multi-stage delivery and changing infrastructure, making isolated IOCs insufficient for tracking the threat. ANY.RUN’s Threat Intelligence helps SOC teams correlate known indicators with related samples, infrastructure, and recurring behavioral patterns.

Threat Intelligence Lookup allows analysts to investigate Phantom Stealer activity and uncover related artifacts beyond a single suspicious sample.

threatName:"phantomstealer"

TI Lookup shows that PhantomStealer targets manufacturing and tech companies in the EU TI Lookup shows that PhantomStealer targets manufacturing and telecoms companies in the EU

Detect Beyond Static IOCs

Defenders should combine traditional indicators with behavioral detections. Useful signals associated with Phantom Stealer activity include:

  • Suspicious business-themed phishing attachments
  • RAR archives containing BAT or script files
  • Heavily obfuscated batch or PowerShell commands
  • Large encoded PowerShell payloads
  • Unexpected PowerShell activity originating from user-opened documents or archives
  • Process injection into legitimate Windows processes
  • Browser processes launched with unusual command-line arguments
  • Unexpected access to browser credential and cookie stores
  • Connections to Telegram, Discord, FTP, or SMTP infrastructure from unusual processes
  • Attempts to access cryptocurrency wallet files or extensions

Behavior-based detection is particularly valuable because Phantom Stealer is commercially distributed and its infrastructure can change between campaigns.

Fresh ANY.RUN’s Threat Intelligence Feeds enriched by data from 16,000 organizations and 700,000 security professionals, provide SOC teams with up-to-date indicators of Phantom Stealer activity. These feeds can be integrated with SIEM, SOAR, and EDR platforms, and other security controls to help identify malicious infrastructure and maintain visibility as the threat evolves.

High-confidence IOCs powered by data from 16K SOCs and 700K analysts High-confidence IOCs powered by data from 16K SOCs and 700K analysts

Connect Individual Samples to the Wider Campaign

Analysts can use ANY.RUN’s Threat Intelligence Lookup to trace Phantom Stealer indicators across related samples, infrastructure, and historical sandbox activity.

For example, a suspicious batch file can be investigated alongside:

  • Related Phantom Stealer samples
  • Shared hashes or code characteristics
  • Associated command-and-control infrastructure
  • Similar PowerShell loaders
  • Common persistence mechanisms
  • Related phishing attachments
  • Previous sandbox executions

This approach helps analysts identify campaign relationships that may not be visible from a single IOC.

Respond to Phantom Stealer Infections

If Phantom Stealer is confirmed on a corporate endpoint, incident response should focus on both the infected system and the credentials that may have been exposed.

Recommended actions include:

  • Isolate the affected endpoint.
  • Reset credentials stored or used on the compromised system.
  • Revoke active sessions where supported.
  • Investigate authentication activity for suspicious logins.
  • Review browser-stored credentials and corporate password-manager access.
  • Monitor cryptocurrency wallets and financial accounts if applicable.
  • Search the environment for related malware, infrastructure, and persistence mechanisms.
  • Preserve forensic evidence before rebuilding the affected endpoint.

Because Phantom Stealer can steal session cookies in addition to passwords, simply changing a password may not remove every form of attacker access.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Phantom Stealer illustrates the growing accessibility of information theft through the Malware-as-a-Service model. By combining broad data collection with phishing-based delivery, obfuscation, process injection, and in-memory execution, the malware can turn a single compromised Windows endpoint into a source of credentials, session data, financial information, and other sensitive assets.

For defenders, detecting Phantom Stealer requires more than blocking known hashes and domains. Behavioral monitoring, interactive malware analysis, endpoint telemetry, and threat intelligence correlation can help identify both individual infections and the broader campaigns behind them.

Frequently Asked Questions: Phantom Stealer

1. What is Phantom Stealer?

Phantom Stealer is a Windows-focused Malware-as-a-Service infostealer designed to harvest credentials, cookies, financial information, cryptocurrency wallets, and other sensitive data.

2. What does Phantom Stealer steal?

Phantom Stealer can target browser passwords, cookies, payment information, cryptocurrency wallets, screenshots, clipboard contents, keystrokes, system information, and data from applications such as Discord, Telegram, and Steam.

3. How is Phantom Stealer delivered?

Recent campaigns have used phishing emails containing compressed archives and malicious scripts or executables disguised as legitimate business documents.

4. How does Phantom Stealer evade detection?

Variants use obfuscation, PowerShell loaders, process injection, and in-memory execution. Some recent campaigns have injected the payload into legitimate processes such as explorer.exe.

5. How can organizations use interactive sandboxing and threat intelligence to detect Phantom Stealer?

Interactive sandboxing allows analysts to observe Phantom Stealer’s execution chain in real time, including wscript.exe launching a JavaScript loader, WMI activity, hidden PowerShell execution, remote payload retrieval, in-memory loading, and browser targeting. Proactive threat intelligence can then help pivot from observed indicators to related samples, infrastructure, and previous Phantom Stealer activity.

HAVE A LOOK AT

Mallox screenshot
Mallox
mallox
Mallox is a ransomware strain that emerged in 2021, known for its ability to encrypt files and target database servers using vulnerabilities like RDP. Often distributed through phishing campaigns and exploiting exposed SQL servers, it locks victims' data and demands a ransom. Mallox operates as a Ransomware-as-a-Service (RaaS), making it accessible to affiliates who use it to conduct attacks.
Read More
PhantomEnigma screenshot
PhantomEnigma
phantomenigma
PhantomEnigma (also known as Operation Phantom Enigma) is a sophisticated crimeware operation primarily targeting banking organizations and the public sector in Brazil. The campaign is characterized by its strategic abuse of compromised legitimate infrastructure, specifically Brazilian government (.gov.br) portals and municipal websites, to host and distribute malicious payloads.
Read More
MetaStealer screenshot
MetaStealer
metastealer
MetaStealer is an info-stealing malware primarily targeting sensitive data like login credentials, payment details, and browser history. It typically infects systems via phishing emails or malicious downloads and can exfiltrate data to a command and control (C2) server. MetaStealer is known for its stealthy techniques, including evasion and persistence mechanisms, which make it difficult to detect. This malware has been actively used in various cyberattacks, particularly for financial theft and credential harvesting from individuals and organizations.
Read More
Remus Stealer screenshot
Remus Stealer is a sophisticated 64-bit information stealer operating under a Malware-as-a-Service (MaaS) model. Identified as a direct evolution of the infamous Lumma Stealer, Remus specializes in harvesting credentials, cookies, and cryptocurrency wallets while utilizing blockchain technology for command-and-control (C2) resilience.
Read More
Sneaky 2FA screenshot
Sneaky 2FA
sneaky2fa
Sneaky 2FA is an Adversary-in-the-Middle (AiTM) phishing kit targeting Microsoft 365 accounts. Distributed as a Phishing-as-a-Service (PhaaS) through a Telegram bot, this malware bypasses two-factor authentication (2FA) to steal credentials and session cookies, posing a significant threat to individuals and organizations.
Read More
MicroStealer screenshot
MicroStealer
microstealer
MicroStealer is a rapidly emerging infostealer first prominently observed in late 2025. It specializes in stealing browser credentials, active session data, screenshots, cryptocurrency wallets, and system information. It spreads quickly with low detection rates thanks to a sophisticated multi-stage delivery chain and exfiltrates data via Discord webhooks and attacker-controlled servers.
Read More