Operation PhantomCLR: Advanced AppDomain Hijacking Targets Financial Sectors

Operation PhantomCLR: Advanced AppDomain Hijacking Targets Financial Sectors

First seen 20 Apr 2026, 21:13 UTC CyfirmaGbhackersCybersecuritynews 80% similarity 66.8

Article Content

Browse articles
ThreatCluster

A sophisticated cyber attack campaign, named Operation PhantomCLR, has been identified, targeting organizations in the Middle East and EMEA financial sectors. The attackers exploit a legitimate Intel utility, IAStorHelp.exe, using .NET AppDomainManager to execute malicious code without altering the original signed binary. This method allows the malware to bypass traditional security measures, including EDR and antivirus solutions. Once the command-and-control communication is established via Amazon CloudFront, attackers can access sensitive data such as credentials and financial records. The malware employs anti-forensic techniques to erase memory artifacts, complicating post-incident investigations. The attack demonstrates a significant evolution in attacker tradecraft, emphasizing the need for advanced detection mechanisms. Organizations affected should consider their systems fully compromised and prepare for potential lateral movement by the adversary.

Key Points: • Operation PhantomCLR exploits a legitimate Intel utility for stealthy malware deployment. • The attack targets financial sectors in the Middle East and EMEA, indicating a broad impact. • Traditional security measures are bypassed, necessitating advanced detection strategies.

ThreatCluster AI How this analysis works

Timeline

2026-04-18
Cyfirma publishes report on Operation PhantomCLR.
2026-04-20
Cybersecuritynews reports on the attack campaign.

Community

Browse all →