Phantom Stealer is an information-stealing malware operation and malware-as-a-service offering marketed under the PhantomStealer brand, including the alias PhantomStealer and operator branding associated with Oldphantomoftheopera. It has been advertised via Telegram and sold as a commercial service with builder access, indicating a multi-operator criminal ecosystem rather than a single closed intrusion set. Phantom Stealer is used primarily for credential theft and financial cybercrime. Reported targeting includes phishing campaigns aimed at Russian users as well as trade-, invoice-, and payment-themed lures directed at business personnel such as procurement, shipping, and accounts receivable staff. The malware has also been associated with adult-content-themed lures and sextortion-adjacent functionality. Functionally, Phantom Stealer is designed to harvest a broad range of sensitive data from infected Windows systems. Documented collection includes browser passwords, cookies, autofill data, payment card data, email client data, messaging application data, FTP and file-transfer credentials, Wi-Fi credentials, selected local files, and cryptocurrency wallet data. It has specifically targeted stored WinSCP credentials, aligning with ATT&CK technique T1552.001 (Credentials In Files). Reported wallet theft coverage includes both desktop wallets and numerous browser wallet extensions. Some variants also include a cryptocurrency clipper that replaces copied wallet addresses in the clipboard with attacker-controlled alternatives. Observed delivery chains have used heavily obfuscated JavaScript droppers, PowerShell loaders, reflective .NET loading, and process hollowing into legitimate Windows .NET utilities for defense evasion. Anti-analysis and evasion behaviors reported in Phantom Stealer-related samples include script obfuscation, custom XOR-based decryption, encrypted configuration storage, sandbox and process checks, self-deletion, and other loader-layer stealth mechanisms. Exfiltration mechanisms have included SMTP, and some builds appear configurable for multiple channels depending on operator settings. Phantom Stealer has been described in at least one campaign as being based on the open-source Stealerium codebase, and it has also been noted to share features with Warp Stealer, suggesting lineage within the broader commodity stealer ecosystem. Additional reported functionality includes a module referred to as PornDetector, which captures webcam screenshots during visits to pornographic sites and is consistent with sextortion-oriented abuse. Overall, Phantom Stealer is best characterized as a commercially operated infostealer brand used by cybercriminal operators for credential theft, data exfiltration, cryptocurrency theft, and related financially motivated activity. High-confidence reporting supports its role as an actively marketed MaaS ecosystem with multiple operators, broad credential-access objectives, and delivery through phishing and staged script-based infection chains.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
24 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential theft activity targeting WinSCP configuration storage to harvest stored SSH/FTP credentials for exfiltration.
Commercial Malware-as-a-Service operator behind PhantomStealer v3.5.0, providing builder access and infrastructure for information-stealing campaigns. The observed deployment used a four-stage JScript-to-PowerShell-to-.NET loader chain, process hollowing into Aspnet_compiler.exe, SMTP-based exfiltration, and a crypto-clipper module to steal credentials, browser data, wallet data, and sensitive files.
Running a high-tempo phishing and credential-stealing campaign using fake invoice and trade-themed lures, compromised legitimate infrastructure, obfuscated JavaScript droppers, encrypted PowerShell loaders, and process hollowing to deliver SnakeKeylogger/VIPKeylogger.
Phantom Stealer is an information stealer malware targeting Russian users, collecting sensitive data and webcam screenshots for potential sextortion, delivered via phishing emails with adult content and payment themes.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.