Phantom Stealer is a .NET-based Windows information-stealing malware family, including malware-as-a-service offerings and variants derived from the open-source Stealerium codebase. It is designed to harvest browser credentials, saved passwords, cookies, session tokens, autofill and payment data, cryptocurrency wallet information, clipboard contents, system information, and data from applications such as FTP and SSH clients, email clients, messaging applications, and VPN tools. Some observed variants also support keylogging, screenshot capture, and theft of financial or wallet-related data.
Phantom Stealer has been delivered in multiple phishing campaigns using business-themed lures and compressed archive attachments containing obfuscated JavaScript, batch, VBScript, or PowerShell loaders. Other observed distribution channels include trojanized or cracked software and malicious downloads or links. Several campaigns used heavily obfuscated, fileless or memory-resident execution chains with layered decoding and decryption, reflective .NET loading, and process injection or process hollowing into legitimate Windows processes to reduce on-disk artifacts and evade detection.
Observed behavior includes host and application enumeration, access to browser profile stores, theft of cookies and active sessions, collection of wallet and messaging data, compression or staging of harvested information, and exfiltration over multiple channels. Reported exfiltration methods include HTTPS POST as well as SMTP with authenticated and encrypted sessions; some reporting also attributes Telegram, Discord, and FTP exfiltration support to the family. Persistence has been observed or reported through registry Run keys, scheduled tasks, dropped scripts, and other re-execution mechanisms. Anti-analysis and defense-evasion features reported across campaigns include obfuscated PowerShell, hidden Unicode or encoded strings, anti-VM checks, disguised API usage, and in-memory execution.
Phantom Stealer is widely used in the cybercriminal ecosystem and has appeared alongside other commodity malware families in shared delivery infrastructure and crypter-enabled campaigns. It has been associated with phishing operations targeting banks and other high-value organizations, and separate activity has targeted sectors including logistics, manufacturing, technology, and finance. Its theft of browser credentials and session material creates substantial downstream risk, including account takeover, financial fraud, and follow-on enterprise intrusion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
35 distinct techniques documented for this family, organized by ATT&CK tactic.
Activation is handled via WMI: GetObject("winmgmts:").Get("Win32_Process").Create("cmd.exe /c C:\Users\Public\SeedComplex.bat")
anti-VM checks, persistence via registry or scheduled task... Persistence through task scheduler, registry, or dropped scripts
anti-VM checks, persistence via registry or scheduled task... Persistence through task scheduler, registry, or dropped scripts
This campaign is a textbook example... combining open-source code (Stealerium base), deep obfuscation, and skilled loader engineering... pushing the boundary of what’s possible with “just scripts”
Assembles and executes a PowerShell payload responsible for the next stage of infection and, crucially, the reflective code injection that is Phantom’s trademark.
Activation is handled via WMI: GetObject("winmgmts:").Get("Win32_Process").Create("cmd.exe /c C:\Users\Public\SeedComplex.bat")
Stage 1: VBScript Dropper... The dropper constructs Scripting.FileSystemObject and writes a heavily obfuscated batch file...
In observed Phantom Stealer campaigns, the malware is typically delivered through phishing lures or cracked software bundles targeting Windows users. Upon initial execution from a user profile or temporary directory, the malware rapidly enumerates installed applications...
anti-VM checks, persistence via registry or scheduled task... Persistence through task scheduler, registry, or dropped scripts
anti-VM checks, persistence via registry or scheduled task... Persistence through task scheduler, registry, or dropped scripts
anti-VM checks, persistence via registry or scheduled task... Persistence through task scheduler, registry, or dropped scripts
Implements advanced memory scanning, process hollowing, and fully in-memory payload execution... classic process hollowing against MSBuild.exe or similar.
The script’s surface was a tangled web of Chr() arithmetic, farm-themed variable names, and aggressive string concatenation... Junk strings replace executable commands... split into multiple fragments and littered with “mango”/“avocadopapaya” to defeat automated forensics.
Implements advanced memory scanning, process hollowing, and fully in-memory payload execution... classic process hollowing against MSBuild.exe or similar.
Implements advanced memory scanning, process hollowing, and fully in-memory payload execution... classic process hollowing against MSBuild.exe or similar.
It wasn’t simply Base64, it was Base64 + XOR + donut.
Phantom Stealer is a .NET-based credential-harvesting malware designed to stealthily steal browser credentials, saved passwords, session cookies, cryptocurrency wallet data, clipboard contents, and system information
A stolen session cookie is not a stolen passkey. An infostealer may take an already authenticated browser session and bypass the login screen entirely.
WinSCP stores sensitive SSH and FTP session credentials, including passwords and private key references, under the user profile path Martin Prikryl\WinSCP 2\Configuration\Security. Information-stealing malware such as Phantom Stealer targets this directory to harvest stored credentials for exfiltration.
Full device fingerprinting — hardware, software, Wi-Fi profiles, environment info.
Potential webcam and screenshot exfiltration for blackmail or further intrusion.
Phantom Stealer is a .NET-based credential-harvesting malware designed to stealthily steal browser credentials, saved passwords, session cookies, cryptocurrency wallet data, clipboard contents, and system information
Following collection, Phantom Stealer compressed the harvested data into an archive and transmitted it via HTTPS POST to its command-and-control server.
If the key is not found, the client sends a 'sendplugin' command to the C2 server ... The C2 server then responds with the command 'savePlugin' along with a base64 encoded string containing the plugin | We observed XWorm RAT Operators execute additional malware, such as: DarkCloud Stealer ... Remcos RAT
Following collection, Phantom Stealer compressed the harvested data into an archive and transmitted it via HTTPS POST to its command-and-control server.
33 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
42 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A stealer referenced in connection with theft of browser cookies and active authenticated sessions.
A .NET-based information-stealing malware that harvests browser credentials, saved passwords, session cookies, cryptocurrency wallet data, clipboard contents, and system information, while maintaining persistence and evading detection. The content says it is commonly distributed through phishing emails, cracked software, Discord, Telegram, and malicious links.
Information stealer distributed via Cruciferra.
An information-stealing malware that harvests host information, installed applications, browser credentials, cookies, stored payment information, cryptocurrency wallet data, and messaging application data, then exfiltrates the stolen information over authenticated SMTP with STARTTLS.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.