Phantom Stealer Campaign is a threat campaign tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed December 13, 2025; most recent activity December 13, 2025.
Phantom Stealer Campaign is a Windows-focused threat operation delivering a payload known as Phantom Stealer. The campaign is notable for using ISO mounting as its delivery vector, illustrating an ISO-based infection approach for stealer malware and highlighting its potential impact on Windows endpoints.
A sophisticated phishing campaign has been identified, originating in Russia, that deploys the Phantom information-stealing malware through malicious ISO files. This operation, named 'Operation MoneyMount-ISO,'…