PhantomStealer is a malware-as-a-service information-stealer operation marketed under the PhantomStealer brand, including the Telegram identity Oldphantomoftheopera. It has been observed both as a commercially offered stealer service and as malware delivered in phishing campaigns. Reported variants include a .NET-based PhantomStealer v3.5.0 and a Stealerium-based Phantom Stealer used in campaigns targeting Russian users. PhantomStealer is designed for credential theft and data exfiltration. Observed capabilities include theft of browser passwords, cookies, autofill data, payment card data, email client data, WinSCP sessions, FileZilla credentials, Discord and Telegram data, Wi-Fi passwords, selected local files, and cryptocurrency wallet data, including browser wallet extensions. Some builds also include a crypto-clipper component that replaces copied wallet addresses in the clipboard. Reporting also attributes a webcam screenshot module used in adult-content-themed campaigns, consistent with sextortion-oriented abuse. Delivery has relied on phishing lures such as invoices, trade documents, payment themes, and adult-content baits. Observed infection chains use heavily obfuscated JavaScript droppers, PowerShell decryptors and loaders, reflective .NET loading, and process hollowing into legitimate Windows .NET binaries. Anti-analysis and defense-evasion measures reported across samples include script obfuscation, custom XOR decryption, AES-encrypted configuration, sandbox and process checks, self-deletion, and process hollowing. Some builds were configured to exfiltrate stolen data over SMTP using compromised third-party mail infrastructure rather than attacker-owned servers. PhantomStealer has targeted stored credentials in applications such as WinSCP and has been associated with campaigns aimed at procurement, shipping, and accounts receivable personnel involved in international trade. Separate reporting describes phishing attacks aimed at Russia delivering a Stealerium-derived Phantom Stealer variant. The operation is best characterized as financially motivated cybercrime centered on credential theft, data theft, and cryptocurrency theft.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
24 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential theft activity targeting WinSCP configuration storage to harvest stored SSH/FTP credentials for exfiltration.
Commercial Malware-as-a-Service operator behind PhantomStealer v3.5.0, providing builder access and infrastructure for information-stealing campaigns. The observed deployment used a four-stage JScript-to-PowerShell-to-.NET loader chain, process hollowing into Aspnet_compiler.exe, SMTP-based exfiltration, and a crypto-clipper module to steal credentials, browser data, wallet data, and sensitive files.
Running a high-tempo phishing and credential-stealing campaign using fake invoice and trade-themed lures, compromised legitimate infrastructure, obfuscated JavaScript droppers, encrypted PowerShell loaders, and process hollowing to deliver SnakeKeylogger/VIPKeylogger.
Phantom Stealer is an information stealer malware targeting Russian users, collecting sensitive data and webcam screenshots for potential sextortion, delivered via phishing emails with adult content and payment themes.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.