Phantom Stealer is a modular, .NET-based information-stealing malware family targeting Windows endpoints. It harvests saved browser credentials, cookies, session tokens, autofill entries, browsing history, and payment-card data from Chromium- and Gecko-based browsers. It also targets cryptocurrency wallets and browser wallet extensions, messaging application sessions, email client data, FTP and SSH client credentials, Wi-Fi passwords, and selected local files. Additional surveillance capabilities include keylogging, screenshot capture, clipboard collection, and host and installed-application discovery. Its cryptocurrency clipboard replacement functionality can substitute attacker-controlled wallet addresses to redirect payments.
Distribution methods include phishing emails, cracked or pirated software, and malicious links circulated through Discord and Telegram. Observed phishing campaigns use shipping, banking, and tax-themed lures, including impersonation of UPS and the Malaysian Inland Revenue Board. Infection chains frequently begin with compressed archives containing obfuscated JavaScript, followed by hidden PowerShell execution and staged .NET loading. Loaders can conceal encoded or encrypted payloads in PNG resources or JPEG images, execute assemblies in memory, and use process injection or process hollowing to deploy the stealer within legitimate Windows processes.
Phantom Stealer checks for virtualization, sandbox environments, analysis tools, and suspicious host or network characteristics before collecting data. It can delay or terminate execution when analysis is suspected and establish persistence through registry autorun entries and Startup-folder entries. Harvested information is packaged into archives and exfiltrated, with multiple campaigns using authenticated SMTP and STARTTLS. The family is used within the commodity cybercrime ecosystem, has been deployed by XWorm operators, and has been distributed using the Cruciferra crypter service.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
42 distinct techniques documented for this family, organized by ATT&CK tactic.
“The malware also uses different persistence techniques, including startup entries and scheduled tasks & services, to remain on the system.”
A PowerShell script loads the .NET assembly, using Base64-decoded data extracted from a JPG, into process memory.
The loader reverses strings and uses Base64-encoded data, including data extracted from a JPG, to conceal the assembly, URL, and payload.
“The script searches the file for the pattern BaseStart-(.*?)-BaseEnd. The data found between BaseStart- and -BaseEnd is then Base64-decoded” and “the file is actually a JPG image.”
If analysis is detected, the malware terminates and cleans itself up using SelfDestruct.Melt(); CAPA also identified file deletion.
The input string is reversed and Base64-decoded to reveal a payload URL; downloaded content is then reversed and Base64-decoded into executable bytes.
Main() calls AntiAnalysis.Run(); if a sandbox or virtualized environment is detected, the malware terminates and invokes SelfDestruct.Melt().
AntiAnalysis checks hosting-provider status, GPU adapters, running processes and services, sandbox DLLs, external IPs, hostname, username, and MachineGuid values against blocklists.
ChromiumRecovery / GeckoRecovery extract stored session cookies from Chromium- and Gecko-based browsers.
Wifi extracts stored Wi-Fi passwords, while FileGrabber searches for files matching targeted extensions across the filesystem.
AntiAnalysis.SuspiciousMachineGuid() matches the registry MachineGuid value against known analysis systems.
The malware queries ip-api.com/json to inspect the current connection and contains WiFi functionality for network discovery.
AntiAnalysis.SuspiciousPCUsername() checks the current username against a list of known automated-analysis profiles.
AntiAnalysis.SuspiciousProcess() checks currently running processes against analysis and monitoring tools, including VmRemoteGuest.exe and Sysmon64.exe.
SystemInfo gathers system metadata, hardware configurations, and OS details; anti-analysis also evaluates GPU and host characteristics.
CAPA mapping includes File and Directory Discovery, and FileGrabber searches the filesystem for files matching selected extensions.
Main() calls AntiAnalysis.Run(); if a sandbox or virtualized environment is detected, the malware terminates and invokes SelfDestruct.Melt().
AntiAnalysis checks hosting-provider status, GPU adapters, running processes and services, sandbox DLLs, external IPs, hostname, username, and MachineGuid values against blocklists.
Telegram scrapes desktop session files; Outlook/FoxMail recover email data; FileZilla/WinSCP recover stored connection data; FileGrabber stages targeted files.
Clipper / ClipLogger monitors and intercepts clipboard contents; CAPA also identifies Clipboard Data collection.
38 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
45 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Modular Windows information stealer with extensive anti-analysis checks. It collects Chromium- and Gecko-browser credentials, cookies, card/autofill data, cryptocurrency wallet data, Discord and Telegram session material, email and FTP/SFTP-client credentials, Wi-Fi passwords, selected files, screenshots, clipboard contents, and keystrokes. It can replace cryptocurrency addresses in the clipboard, establish Run-key/startup persistence, execute commands or secondary payloads, archive stolen data, and exfiltrate it via SMTP; the analyzed configuration enabled SMTP exfiltration.
Information-stealing malware delivered through a phishing archive containing obfuscated JavaScript. The staged execution chain downloads additional JavaScript, launches hidden PowerShell, extracts a Base64-encoded .NET assembly concealed inside a valid JPG file, and loads that assembly directly in memory. It establishes persistence via startup entries and scheduled tasks/services, collects information from the compromised host, and sends it to the attacker.
Phantom Stealer is a modular, .NET-based information stealer targeting Windows users through phishing emails, pirated software, and malicious links shared on Discord and Telegram. Observed loaders conceal encrypted payloads in PNG resources or use obfuscated PowerShell to inject code into explorer.exe and interfere with security scanning and event logging. The malware steals browser credentials, session cookies, payment-card data, cryptocurrency wallet material, selected files, application credentials, screenshots, keystrokes, and saved Wi-Fi profiles. It can replace clipboard wallet addresses with attacker-controlled addresses, persist through Registry Run entries or the Startup folder, and delay or stop execution when it detects analysis environments.
A stealer referenced in connection with theft of browser cookies and active authenticated sessions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.