Phantom — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
10
occurrences
First Seen
December 1, 2025
Last Seen
July 1, 2026

Phantom is a technology platform tracked across 7 threat clusters and 10 intelligence report mentions on ThreatCluster. First observed December 1, 2025; most recent activity July 1, 2026.

Overview

Phantom Stealer is a Windows-targeted information-stealing malware campaign that delivers its payload via ISO mounting, enabling covert execution and data exfiltration from infected hosts. The campaign demonstrates the use of removable-media-like delivery techniques to deploy stealer payloads, underscoring persistent risk from information-stealer families in the cybersecurity landscape.

Related Threat Clusters

Recent Intelligence Reports

  • DeFi devs, Polymarket trading bot users targeted in fresh info — Cryptopolitan · July 1, 2026
  • EtherHiding — www.bleepingcomputer.com · May 26, 2026
  • Cybercriminals Deploy Torg Grabber Malware to Target 728 Crypto Wallet Extensions — Bitget · March 27, 2026
  • SlowMist Warns MetaMask Users of Sophisticated Fake 2FA Phishing Scam — Coinpedia · January 5, 2026
  • Plagued by Fake Software and Phishing Attacks, While Direct Official Vulnerabilities Are Rare — Bitget · December 26, 2025
  • Plagued by Counterfeit Software and Phishing Attacks, Direct Official Vulnerabilities Are Few — Bitget · December 26, 2025
  • Plagued by Counterfeit Software and Phishing Attacks, Direct Official Vulnerabilities Are Few — Bitget · December 26, 2025
  • New Phantom Stealer Campaign Hits Windows Machines Through ISO Mounting — Cybersecuritynews · December 13, 2025

CVSS v3.1 Breakdown