Phantom Stealer Malware-as-a-Service Infostealer Analysis
Score: 8/10

Phantom Stealer Malware-as-a-Service Infostealer Analysis

Oldphantomoftheopera and Phantom Softwares operate Phantom Stealer, a Malware-as-a-Service infostealer targeting Windows systems through multi-stage in-memory execution and obfuscated PowerShell to harvest credentials and cryptocurrency data.

Executive Summary

Phantom Stealer is a sophisticated, commercially available Malware-as-a-Service (MaaS) infostealer targeting Windows endpoints. Attributed to actors known as Oldphantomoftheopera and the group Phantom Softwares, the malware is designed to harvest a wide array of sensitive information, including browser-stored credentials, session cookies, payment data, cryptocurrency wallets, and keystrokes.

The infection chain is notably evasive, employing a multi-stage process that utilizes wscript.exe, WMI, and hidden PowerShell to download and decode a final payload disguised as a PNG file. By leveraging in-memory execution via .NET assemblies, the malware significantly reduces its on-disk footprint, complicating traditional file-based detection.

The threat is particularly potent for corporate environments as it targets data from major browsers (Chrome, Firefox, Edge) and popular communication platforms like Telegram and Discord. Stolen session cookies further enable session hijacking, potentially bypassing password-based protections.

Key Details

Threat Name

Phantom Stealer

Affects

—

Adversary

Oldphantomoftheopera Other Adversaries and Aliases: Phantom Softwares

Malware/Tools

Phantom Stealer, HVNC Backdoor, FatalRAT, Miolab Stealer, DoubleTrouble, Agent Tesla, GREENBLOOD, Octo

Report Score

8out of 10
Quality Score
Good
IOC Quality8
TTP Details9
Detection Guidance6
Enterprise Relevance9
Clarity & Structure9
Technical Depth8

Sources