Abusing Trusted Business Workflows: A Multi-Stage Phantom Stealer Campaign
released on 2026-07-22 @ 03:17:48 PM
A sophisticated phishing campaign impersonates legitimate business entities including UPS and the Malaysian Inland Revenue Board to distribute Phantom Stealer v3.5.0. The attack begins with convincing emails containing compressed archives housing malicious JavaScript files. Once executed, the JavaScript launches obfuscated PowerShell scripts that operate entirely in memory, deploying multiple stages of encrypted and encoded payloads. The infection chain utilizes Base64 encoding, AES encryption, and XOR ciphering to conceal its activities. The final payload, Phantom Stealer, harvests credentials from browsers, cryptocurrency wallets, messaging applications, and system information before exfiltrating stolen data via SMTP over port 587 using STARTTLS encryption. The multi-layered approach significantly reduces on-disk footprint and employs reflective code loading and process injection into legitimate binaries to evade traditional security defenses.