Executive Summary
Phantom Stealer is a sophisticated, commercially available Malware-as-a-Service (MaaS) infostealer targeting Windows endpoints. Attributed to actors known as Oldphantomoftheopera and the group Phantom Softwares, the malware is designed to harvest a wide array of sensitive information, including browser-stored credentials, session cookies, payment data, cryptocurrency wallets, and keystrokes.
The infection chain is notably evasive, employing a multi-stage process that utilizes wscript.exe, WMI, and hidden PowerShell to download and decode a final payload disguised as a PNG file. By leveraging in-memory execution via .NET assemblies, the malware significantly reduces its on-disk footprint, complicating traditional file-based detection.
The threat is particularly potent for corporate environments as it targets data from major browsers (Chrome, Firefox, Edge) and popular communication platforms like Telegram and Discord. Stolen session cookies further enable session hijacking, potentially bypassing password-based protections.
Key Details
Threat Name
Phantom Stealer
Affects
—
Adversary
Oldphantomoftheopera Other Adversaries and Aliases: Phantom Softwares
Malware/Tools
Phantom Stealer, HVNC Backdoor, FatalRAT, Miolab Stealer, DoubleTrouble, Agent Tesla, GREENBLOOD, Octo
