ThreatCluster

Phantom Stealer Campaign Targets Finance Departments via ISO Files

First seen 13 Dec 2025, 15:48 UTC Cybersecuritynews 100% similarity 27

Article Content

Browse articles
ThreatCluster

A sophisticated phishing campaign has been identified, originating in Russia, that deploys the Phantom information-stealing malware through malicious ISO files. This operation, named 'Operation MoneyMount-ISO,' specifically targets finance and accounting departments by using fake payment confirmation emails to deceive victims into executing the malware.

ThreatCluster AI

Community

Browse all →