Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Phantom Stealer

140
Global rank
93 infographic chevron month
Month rank
202 infographic chevron week
Week rank
0
IOCs

Phantom Stealer is a commercially available Malware-as-a-Service infostealer targeting Windows systems. It harvests browser passwords, session cookies, payment data, cryptocurrency wallets, system information, screenshots, and application data.

Stealer
Type
Unknown
Origin
1 October, 2025
First seen
4 September, 2026
Last seen

How to analyze Phantom Stealer with ANY.RUN

Type
Unknown
Origin
1 October, 2025
First seen
4 September, 2026
Last seen

IOCs

IP addresses
91.189.91.65
91.189.91.97
185.125.190.56
185.125.190.57
185.125.188.54
91.189.91.99
185.125.188.61
185.125.188.60
91.189.91.96
185.125.190.99
185.125.188.55
20.190.160.131
74.178.76.128
57.153.246.3
128.24.231.65
23.11.41.157
88.221.169.152
88.221.169.205
48.209.133.15
172.211.123.250
Hashes
03ff10f626253ac8613b7c489170d602c524b9e8b69ebc13d677a800b0bdb0db
6a1e573c0068dc87d4f0fbe6782d0a253dd60b9f37b7f6c5c4d6c72547f16c05
4377e894b3e7956b74d467118164b7023e9b0f0f4c151e464d00991e30f924ac
f9120c06aad5aa4add1b646456199fd34b4fa72c6eb8ba4d37d85a59d7cac478
3aa5fcb894a4dacabbedf7995d0d94dcf53d1faf5114089f685c120895a0e26a
d2501059efb3723eafb1bc76f2209a48bdcc9568edfc012d259748fe8a9011f6
ddb9d916b9a350009121972942e22143cc9b2fba3bb4c59652270a27923ee952
06d336004f0800f8e10b602dc7a7f27b5f4988b998c3b6cd2807d65787374472
e1625a8c19a4444ac3e51383cab16eb7887e7887bdbf248902ee5974ea29de51
69f23d8f20eee02cd610ec7502d991e097b031c03a4f445439f2bc287cbdf6ec
a12494709523898db3239fd4996ee77b9c19760b24c029e0292d682e46b7558b
bdbaed48a04034e6bad2d2cb32211f594a21bc1195517d58deaaff137634ccaf
028a45e4ab43094b9910a58a6ca17dc0f73226fd08546010f7a96e57c92a4479
33adcc541093fffa0afbf1cef997646cccd0451266af88f9c2c2949ac4d6366c
345cc95831e9900b0e4f68a1f9afc9bf4190b1790a57eee34864ea556b60f229
e9713a271bd302aecfd50c96818020668d0a56ec40f62eca768a74462bb91d16
e608d06a414aab2f62f08947089828ed93c187be037edcb68d7855cc4516025c
bcd393ff51181c590aab1566a05a5dc067f9c12aa09e2587d4bd4428d250168c
b607a86f2036efd244ce70e0aaceec02e623a91eefb31e19d4e915023feb0182
ac96fc01568ec3cfaf434567d66b73469517f1d41996727e166fba3d26e6d097
Domains
connectivity-check.ubuntu.com
google.com
dashboard.snapcraft.io
api.snapcraft.io
canonical-bos01.cdn.snapcraftcontent.com
slscr.update.microsoft.com
fe3cr.delivery.mp.microsoft.com
self.events.data.microsoft.com
settings-win.data.microsoft.com
www.microsoft.com
go.microsoft.com
client.wns.windows.com
login.live.com
ocsp.digicert.com
nexusrules.officeapps.live.com
crl.microsoft.com
activation-v2.sls.microsoft.com
edge.microsoft.com
ap-1787820228-lecjaf-qa1j5hx4mpoab1mkzt4ni7ybpgygqeuc1b-s3alias.s3.eu-central-1.amazonaws.com
edge-consumer-static.azureedge.net
URLs
http://connectivity-check.ubuntu.com/
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=0&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://settings-win.data.microsoft.com/settings/v3.0/onesettings/client?osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&localdeviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&attrdataver=186&osuilocale=en-us&osskuid=48&app=wosc&appver=&isflightingenabled=0&telemetrylevel=1&devicefamily=windows.desktop
https://login.live.com/rst2.srf
https://login.live.com/ppsecure/deviceaddcredential.srf
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://settings-win.data.microsoft.com/settings/v3.0/flightsettings/fsservice?processorclockspeed=3094&isretailos=1&oemmanufacturername=dell&flightingpolicyvalue=3&enablepreviewbuilds=4294967295&osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&managepreviewbuilds=3&branchreadinesslevelsource=0&attrdataver=186&processorcores=6&branchreadinesslevelraw=16&totalphysicalram=6144&tpmversion=0&oemmodelnumber=dell&systemvolumetotalcapacity=260281&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&app=fss&appver=10.0&smartactivehoursstate=1&activehoursstart=20&securebootcapable=0&activehoursend=13&devicefamily=windows.desktop
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?processorclockspeed=3094&flightids=&updateoffereddays=4294967295&branchreadinesslevel=cb&oemmanufacturername=dell&isclouddomainjoined=0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&sku=48&activationchannel=retail&attrdataver=186&ismdmenrolled=0&processorcores=6&processormodel=amd%20ryzen%205%203500%206-core%20processor&totalphysicalram=6144&primarydisktype=4294967295&flightingbranchname=&chassistypeid=1&oemmodelnumber=dell&systemvolumetotalcapacity=260281&sampleid=95271487&deviceclass=windows.desktop&app=muse&disabledualscan=0&appver=10.0&oemsubmodel=j5cr&locale=en-us&isalwaysonalwaysconnectedcapable=0&ms=0&defaultuserregion=244&updateserviceurl=http%3a%2f%2fneverupdatewindows10.com&osver=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&deferqualityupdateperiodindays=0&ring=retail&deferfeatureupdateperiodindays=30
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20secure%20server%20ca%202.1.crl
https://slscr.update.microsoft.com/sls/%7b522d76a4-93e1-47f8-b8ce-07c937ad1a1e%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
https://slscr.update.microsoft.com/sls/ping
https://slscr.update.microsoft.com/sls/%7be7a50285-d08d-499d-9ff8-180fdc2332bc%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
https://settings-win.data.microsoft.com/settings/v3.0/wsd/updatehealthtools?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=s:bad99146-31d3-4ec6-a1a4-be76f32ba5d4&sampleid=s:95271487&appver=10.0.19041.3626&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=sedimentpack&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:x6rb56uttj3h4ykuryqtaagcdcy9xp7t7s9j9bqs18c&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://copilot.microsoft.com/c/api/user/eligibility
Last Seen at

Recent blog posts

post image
ANY.RUN Secures Leader Status in G2’s Malware...
watchers 4555
comments 0
post image
15 Minutes Saved Per Alert: How a Lean German...
watchers 9232
comments 0
post image
HVNC Backdoor Targets LATAM Organizations wit...
watchers 11209
comments 0

Key Takeaways

  • Credential and Data Theft: Phantom Stealer targets browser passwords, session cookies, payment information, cryptocurrency wallets, and other sensitive data.
  • Windows-Focused Threat: The malware is designed to compromise Windows endpoints and can interact with browsers and applications installed on the victim's system.
  • MaaS Distribution: Phantom Stealer is commercially offered as a Malware-as-a-Service product, allowing multiple threat actors to deploy it in different campaigns.
  • Phishing Delivery: Recent campaigns have used business-themed phishing emails and compressed attachments to deliver the stealer.
  • Evasion-Focused Execution: Variants use obfuscation, PowerShell, process injection, and in-memory execution to reduce the visibility of the payload.
  • Multiple Exfiltration Channels: Stolen information can be sent through channels including Telegram, Discord, SMTP, and FTP.
  • ANY.RUN’s Interactive Sandbox analysis shows Phantom Stealer harvesting browser credentials, session cookies, financial data, and other sensitive information, while using in-memory execution and process injection to evade detection.

What is Phantom Stealer?

Phantom Stealer is a commercially distributed Windows infostealer built to collect valuable information from compromised systems. It targets major web browsers, including Chrome, Firefox, and Edge, harvesting credentials, cookies, payment information, and other browser data.

The malware can also collect cryptocurrency wallet information, screenshots, clipboard contents, keystrokes, system information, and data associated with applications such as Discord, Telegram, and Steam.
Phantom Stealer is offered through a subscription-based Malware-as-a-Service model, lowering the technical barrier for threat actors who want to conduct credential theft and information-stealing campaigns. Recent reporting attributes the operation to an actor using the alias Oldphantomoftheopera and the Phantom Softwares group.

How Phantom Stealer Threatens Businesses and Organizations

A successful Phantom Stealer infection can expose organizations to risks beyond the initial endpoint compromise:

  • Account takeover: Stolen browser passwords and session cookies can provide access to corporate accounts and web applications.
  • Financial loss: Payment information and cryptocurrency wallet data can be targeted for direct financial theft.
  • Credential exposure: Browser-stored credentials can include access to email, SaaS platforms, administrative portals, and other business services.
  • Session hijacking: Stolen cookies and authentication data may allow attackers to reuse existing authenticated sessions.
  • Follow-on attacks: Compromised credentials can provide attackers with additional opportunities for phishing, fraud, and further intrusion.
  • Data exposure: Screenshots, clipboard contents, application data, and system information can reveal additional sensitive information.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Victimology: Who Is Most Vulnerable?

Phantom Stealer can affect organizations across industries because its primary targets — browser credentials, cookies, financial information, and application data — are commonly present on Windows workstations. Recent campaigns have particularly used business-themed phishing lures, including documents and quote-request themes, suggesting targeting of corporate environments.
The MaaS model also means that Phantom Stealer should not be associated with a single victim profile or threat actor. Different operators can deploy the same malware through their own phishing infrastructure and delivery chains.

How Does Phantom Stealer Function?

Observing a Phantom Stealer sample inside ANY.RUN’s Interactive Sandbox reveals a multi-stage infection chain designed to move from phishing delivery to in-memory payload execution and data exfiltration.

The infection chain begins with wscript.exe acting as a launcher and progresses through WMI, hidden PowerShell execution, remote payload retrieval, in-memory loading, and browser targeting.

Phantom Stealer detonated inside ANY.RUN’s Interactive Sandbox Phantom Stealer detonated inside ANY.RUN’s Interactive Sandbox

Stage 1: JavaScript Loader

The infection begins with shim.js, a JavaScript loader executed through wscript.exe. Rather than launching the main payload directly, the script uses WMI to create a hidden PowerShell process.

The observed execution chain is:

JS loader → WMI → PowerShell → remote payload → PE payload

This approach keeps the primary payload separate from the initial JavaScript file and allows the next stages to be retrieved and executed dynamically.

wscript.exe launching the Phantom Stealer JavaScript loader wscript.exe launching the Phantom Stealer JavaScript loader

Stage 2: Hidden PowerShell Execution

The WMI-created PowerShell process runs with several parameters designed to limit visibility and restrictions:

  • -ExecutionPolicy Bypass bypasses the standard PowerShell execution policy.
  • -NoProfile prevents user PowerShell profiles from affecting execution.
  • -WindowStyle Hidden keeps the PowerShell window invisible.

The script then retrieves code from the INTERNAL_DB_CACHE user environment variable and executes it using IEX (Invoke-Expression). Afterward, the variable is deleted, removing the stored value from the user environment.

PowerShell running in hidden mode PowerShell running in hidden mode

Stage 3: Remote Payload Retrieval

The PowerShell stage creates a .NET WebClient and uses DownloadData() to retrieve data from a remote resource over HTTPS.

The downloaded object is presented as a PNG file, allowing the next-stage payload to appear as a legitimate image resource rather than an executable.

PowerShell downloading the second-stage payload via .NET WebClient PowerShell downloading the second-stage payload via .NET WebClient

Stage 4: Payload Decoding

The downloaded bytes are converted into a string and passed through FromBase64String(). The resulting data begins with the MZ signature associated with Windows PE files.

The observed chain is therefore:

HTTPS request → PNG-like data → byte array → Base64 decoding → PE payload

The presence of XICC_PROFILE within the downloaded data further supports the use of image data as a container for the next stage.

PNG file used to deliver the next-stage payload PNG file used to deliver the next-stage payload

Stage 5: In-Memory Loading

Rather than simply writing the decoded executable to disk, the payload is loaded from a byte array using .NET's Load(System.Byte[]). This allows the PE/.NET assembly to be loaded directly into memory, reducing the need for a conventional executable file on disk and making the execution chain harder to detect through file-based analysis alone.

Stage 6: Phantom Process and Browser Targeting

Following the loader activity, AddInProcess32.exe appears in the process tree and is associated with the Phantom payload. The use of a legitimate Windows/.NET component name can make the process appear less suspicious when viewed by name alone.

The process subsequently launches separate instances of:

  • chrome.exe
  • firefox.exe
  • msedge.exe

Each browser is started with its own temporary profile directories. This behavior is consistent with Phantom Stealer's focus on browser environments and provides the malware with access to browser-related authentication and account data.

Overall, the analyzed execution chain combines WMI-based process creation, hidden PowerShell, remote payload retrieval, encoded delivery, in-memory loading, and browser interaction to conceal the stealer and reach its primary data sources.

The Evolution of Phantom Stealer

Phantom Stealer has appeared in multiple variants and delivery chains, with recent campaigns placing significant emphasis on stealth and in-memory execution.

  • Commercial distribution: Phantom Stealer is offered through a MaaS model, allowing different operators to deploy the malware.
  • Multi-stage delivery: Campaigns use layered scripts, loaders, and decoding mechanisms to conceal the final payload.
  • Improved evasion: Recent activity has incorporated process injection and in-memory execution to reduce traditional file-based detection opportunities.
  • Expanded targeting: The malware targets not only browser credentials but also cryptocurrency wallets, financial data, messaging applications, screenshots, and clipboard contents.
  • Flexible exfiltration: Operators can use multiple communication channels to retrieve stolen information.

How Businesses Can Use ANY.RUN’s Threat Intelligence Against Phantom Stealer

Phantom Stealer uses multi-stage delivery and changing infrastructure, making isolated IOCs insufficient for tracking the threat. ANY.RUN’s Threat Intelligence helps SOC teams correlate known indicators with related samples, infrastructure, and recurring behavioral patterns.

Threat Intelligence Lookup allows analysts to investigate Phantom Stealer activity and uncover related artifacts beyond a single suspicious sample.

threatName:"phantomstealer"

TI Lookup shows that PhantomStealer targets manufacturing and tech companies in the EU TI Lookup shows that PhantomStealer targets manufacturing and telecoms companies in the EU

Detect Beyond Static IOCs

Defenders should combine traditional indicators with behavioral detections. Useful signals associated with Phantom Stealer activity include:

  • Suspicious business-themed phishing attachments
  • RAR archives containing BAT or script files
  • Heavily obfuscated batch or PowerShell commands
  • Large encoded PowerShell payloads
  • Unexpected PowerShell activity originating from user-opened documents or archives
  • Process injection into legitimate Windows processes
  • Browser processes launched with unusual command-line arguments
  • Unexpected access to browser credential and cookie stores
  • Connections to Telegram, Discord, FTP, or SMTP infrastructure from unusual processes
  • Attempts to access cryptocurrency wallet files or extensions

Behavior-based detection is particularly valuable because Phantom Stealer is commercially distributed and its infrastructure can change between campaigns.

Fresh ANY.RUN’s Threat Intelligence Feeds enriched by data from 16,000 organizations and 700,000 security professionals, provide SOC teams with up-to-date indicators of Phantom Stealer activity. These feeds can be integrated with SIEM, SOAR, and EDR platforms, and other security controls to help identify malicious infrastructure and maintain visibility as the threat evolves.

High-confidence IOCs powered by data from 16K SOCs and 700K analysts High-confidence IOCs powered by data from 16K SOCs and 700K analysts

Connect Individual Samples to the Wider Campaign

Analysts can use ANY.RUN’s Threat Intelligence Lookup to trace Phantom Stealer indicators across related samples, infrastructure, and historical sandbox activity.

For example, a suspicious batch file can be investigated alongside:

  • Related Phantom Stealer samples
  • Shared hashes or code characteristics
  • Associated command-and-control infrastructure
  • Similar PowerShell loaders
  • Common persistence mechanisms
  • Related phishing attachments
  • Previous sandbox executions

This approach helps analysts identify campaign relationships that may not be visible from a single IOC.

Respond to Phantom Stealer Infections

If Phantom Stealer is confirmed on a corporate endpoint, incident response should focus on both the infected system and the credentials that may have been exposed.

Recommended actions include:

  • Isolate the affected endpoint.
  • Reset credentials stored or used on the compromised system.
  • Revoke active sessions where supported.
  • Investigate authentication activity for suspicious logins.
  • Review browser-stored credentials and corporate password-manager access.
  • Monitor cryptocurrency wallets and financial accounts if applicable.
  • Search the environment for related malware, infrastructure, and persistence mechanisms.
  • Preserve forensic evidence before rebuilding the affected endpoint.

Because Phantom Stealer can steal session cookies in addition to passwords, simply changing a password may not remove every form of attacker access.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Phantom Stealer illustrates the growing accessibility of information theft through the Malware-as-a-Service model. By combining broad data collection with phishing-based delivery, obfuscation, process injection, and in-memory execution, the malware can turn a single compromised Windows endpoint into a source of credentials, session data, financial information, and other sensitive assets.

For defenders, detecting Phantom Stealer requires more than blocking known hashes and domains. Behavioral monitoring, interactive malware analysis, endpoint telemetry, and threat intelligence correlation can help identify both individual infections and the broader campaigns behind them.

Frequently Asked Questions: Phantom Stealer

1. What is Phantom Stealer?

Phantom Stealer is a Windows-focused Malware-as-a-Service infostealer designed to harvest credentials, cookies, financial information, cryptocurrency wallets, and other sensitive data.

2. What does Phantom Stealer steal?

Phantom Stealer can target browser passwords, cookies, payment information, cryptocurrency wallets, screenshots, clipboard contents, keystrokes, system information, and data from applications such as Discord, Telegram, and Steam.

3. How is Phantom Stealer delivered?

Recent campaigns have used phishing emails containing compressed archives and malicious scripts or executables disguised as legitimate business documents.

4. How does Phantom Stealer evade detection?

Variants use obfuscation, PowerShell loaders, process injection, and in-memory execution. Some recent campaigns have injected the payload into legitimate processes such as explorer.exe.

5. How can organizations use interactive sandboxing and threat intelligence to detect Phantom Stealer?

Interactive sandboxing allows analysts to observe Phantom Stealer’s execution chain in real time, including wscript.exe launching a JavaScript loader, WMI activity, hidden PowerShell execution, remote payload retrieval, in-memory loading, and browser targeting. Proactive threat intelligence can then help pivot from observed indicators to related samples, infrastructure, and previous Phantom Stealer activity.

HAVE A LOOK AT

Interlock screenshot
Interlock
interlock
Interlock is a relatively recent entrant into the ransomware landscape. First identified in 2023, it's a multi-functional malware strain used in ransomware-as-a-service (RaaS) operations.
Read More
Remus Stealer screenshot
Remus Stealer is a sophisticated 64-bit information stealer operating under a Malware-as-a-Service (MaaS) model. Identified as a direct evolution of the infamous Lumma Stealer, Remus specializes in harvesting credentials, cookies, and cryptocurrency wallets while utilizing blockchain technology for command-and-control (C2) resilience.
Read More
Sneaky 2FA screenshot
Sneaky 2FA
sneaky2fa
Sneaky 2FA is an Adversary-in-the-Middle (AiTM) phishing kit targeting Microsoft 365 accounts. Distributed as a Phishing-as-a-Service (PhaaS) through a Telegram bot, this malware bypasses two-factor authentication (2FA) to steal credentials and session cookies, posing a significant threat to individuals and organizations.
Read More
PhantomEnigma screenshot
PhantomEnigma
phantomenigma
PhantomEnigma (also known as Operation Phantom Enigma) is a sophisticated crimeware operation primarily targeting banking organizations and the public sector in Brazil. The campaign is characterized by its strategic abuse of compromised legitimate infrastructure, specifically Brazilian government (.gov.br) portals and municipal websites, to host and distribute malicious payloads.
Read More
Mallox screenshot
Mallox
mallox
Mallox is a ransomware strain that emerged in 2021, known for its ability to encrypt files and target database servers using vulnerabilities like RDP. Often distributed through phishing campaigns and exploiting exposed SQL servers, it locks victims' data and demands a ransom. Mallox operates as a Ransomware-as-a-Service (RaaS), making it accessible to affiliates who use it to conduct attacks.
Read More
MetaStealer screenshot
MetaStealer
metastealer
MetaStealer is an info-stealing malware primarily targeting sensitive data like login credentials, payment details, and browser history. It typically infects systems via phishing emails or malicious downloads and can exfiltrate data to a command and control (C2) server. MetaStealer is known for its stealthy techniques, including evasion and persistence mechanisms, which make it difficult to detect. This malware has been actively used in various cyberattacks, particularly for financial theft and credential harvesting from individuals and organizations.
Read More