Skip to content
ThreatCluster

Phantom Stealer Campaign Targets Finance Departments via ISO Files

First seen 13 Dec 2025, 15:48 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

A sophisticated phishing campaign has been identified, originating in Russia, that deploys the Phantom information-stealing malware through malicious ISO files. This operation, named 'Operation MoneyMount-ISO,' specifically targets finance and accounting departments by using fake payment confirmation emails to deceive victims into executing the malware.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 193d ago How this analysis works

More articles in this cluster (2)