Phantom Stealer is a Windows-targeted information-stealing malware campaign that delivers its payload via ISO mounting, enabling covert execution and data exfiltration from infected hosts.
Overview
Phantom Stealer is a Windows-targeted information-stealing malware campaign that delivers its payload via ISO mounting, enabling covert execution and data exfiltration from infected hosts. The campaign demonstrates the use of removable-media-like delivery techniques to deploy stealer payloads, underscoring persistent risk from information-stealer families in the cybersecurity landscape.
Related Threat Clusters
-
Malware Spread via Fake Polymarket Trading Bot Targets DeFi Developers
On July 1, 2026, security firm SlowMist identified a fake trading bot on GitHub designed to spread malware targeting Polymarket users and DeFi developers. The bot, named 'polymarket-arbitrage-bot', was promoted as a…
2 articles · Updated July 1, 2026 -
North Korean Hackers Utilize EtherHiding for Cryptocurrency Theft
The Google Threat Intelligence Group (GTIG) reports that North Korean threat actor UNC5342 has adopted a new technique called EtherHiding to deliver malware and facilitate cryptocurrency theft. This method embeds…
3 articles · Updated May 26, 2026 -
Torg Grabber Malware Targets 728 Crypto Wallets with Advanced Techniques
Torg Grabber, a new infostealer malware, is actively targeting 728 cryptocurrency wallet extensions and other applications, including password managers and communication tools. The malware employs the ClickFix technique…
2 articles · Updated March 27, 2026 -
Trust Wallet Browser Extension Version 2.68 Vulnerability Leads to $6 Million in Losses
Trust Wallet has confirmed a security vulnerability in version 2.68 of its browser extension, leading to the theft of funds from hundreds of users, totaling at least $6 million. Users are advised to disable the…
41 articles · Updated December 26, 2025 -
Phantom Stealer Campaign Targets Finance Departments via ISO Files
A sophisticated phishing campaign has been identified, originating in Russia, that deploys the Phantom information-stealing malware through malicious ISO files. This operation, named 'Operation MoneyMount-ISO,'…
2 articles · Updated December 13, 2025 -
Sophisticated Phishing Scam Targets MetaMask Users' 2FA Security
A new phishing campaign is targeting MetaMask users by mimicking two-factor authentication (2FA) processes to steal wallet recovery phrases. The attack utilizes professional branding and fake emails that appear to be…
5 articles · Updated January 5, 2026 -
Chinese Hackers Utilize AI for Cyberattacks on US Companies
Chinese hackers have leveraged artificial intelligence tools to conduct cyberattacks, with Anthropic, a major US company, reporting a recent incident. The attacks utilize AI models capable of writing code, scanning…
14 articles · Updated November 29, 2025
Recent Intelligence Reports
- DeFi devs, Polymarket trading bot users targeted in fresh info — Cryptopolitan · July 1, 2026
- EtherHiding — www.bleepingcomputer.com · May 26, 2026
- Cybercriminals Deploy Torg Grabber Malware to Target 728 Crypto Wallet Extensions — Bitget · March 27, 2026
- SlowMist Warns MetaMask Users of Sophisticated Fake 2FA Phishing Scam — Coinpedia · January 5, 2026
- Plagued by Fake Software and Phishing Attacks, While Direct Official Vulnerabilities Are Rare — Bitget · December 26, 2025
- Plagued by Counterfeit Software and Phishing Attacks, Direct Official Vulnerabilities Are Few — Bitget · December 26, 2025
- Plagued by Counterfeit Software and Phishing Attacks, Direct Official Vulnerabilities Are Few — Bitget · December 26, 2025
- New Phantom Stealer Campaign Hits Windows Machines Through ISO Mounting — Cybersecuritynews · December 13, 2025