Phantom Stealer Campaign Targets Finance Departments via ISO Files
First seen 13 Dec 2025, 15:48 UTC
•
•100% similarity
•27
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
A sophisticated phishing campaign has been identified, originating in Russia, that deploys the Phantom information-stealing malware through malicious ISO files. This operation, named 'Operation MoneyMount-ISO,' specifically targets finance and accounting departments by using fake payment confirmation emails to deceive victims into executing the malware.
ThreatCluster AI