Oldphantomoftheopera is the branding associated with the operators of PhantomStealer, a commercial malware-as-a-service offering centered on credential and data theft. The actor advertises PhantomStealer builder licenses via Telegram and is linked to the PhantomStealer ecosystem as its operator or seller. Observed delivery chains associated with PhantomStealer use heavily obfuscated multi-stage loaders, including JScript and PowerShell components, followed by a .NET loader that performs process hollowing and injects the final stealer into legitimate Windows processes for defense evasion. PhantomStealer is a .NET information stealer that targets browser credentials, cookies, stored payment-card data, email and messaging artifacts, cryptocurrency wallets, Wi-Fi passwords, and selected local files. It also includes cryptocurrency-clipping functionality that swaps wallet addresses across multiple blockchain ecosystems. Documented tradecraft includes obfuscation, staged decryption, hidden PowerShell execution, process hollowing, process injection, and exfiltration over SMTP using compromised third-party infrastructure. The actor is best characterized as a financially motivated cybercriminal operator supporting commodity infostealer activity rather than a nation-state intrusion set.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
29 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
30 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.