PhantomStealer is a Windows-focused C#/.NET information stealer, observed in both a commercial Malware-as-a-Service ecosystem and deployments associated with the PhantomCore threat actor. It has been distributed through phishing and malspam campaigns using business-themed lures, including invoices, requests for quotation, orders, payments, shipping, and procurement documents. Campaigns have notably targeted Italian recipients as well as maritime shipping, industrial supply-chain, procurement, and accounts-receivable personnel.
Recent versions use heavily obfuscated JavaScript or PowerShell-based multi-stage loaders that decrypt and reflectively load .NET components, then use process hollowing to execute the stealer within legitimate .NET processes. Some delivery chains use an injector that elevates privileges, abuses a vulnerable driver to terminate security products, and injects PhantomStealer into a legitimate process.
PhantomStealer can collect stored credentials, cookies, autofill data, payment-card data, browser wallet data, and authentication material from Chromium- and Gecko-based browsers. It also targets Outlook and other email clients, FTP and remote-access applications, messaging artifacts and tokens, desktop cryptocurrency wallets, saved Wi-Fi credentials, clipboard data, selected local files, and host and network information. Configurable modules support keylogging, screenshot capture, startup persistence, anti-analysis checks, self-deletion, and exfiltration through SMTP, FTP, Telegram, or Discord. Certain builds include a cryptocurrency clipper that replaces cryptocurrency wallet addresses copied to the clipboard. PhantomCore has also used PhantomStealer to export, decrypt, and archive browser authentication data before collection and exfiltration.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
PhantomCore uses its in-house infostealer, PhantomStealer, to export, decrypt, and save as an archive the authentication data stored on the infected host in Chrome and Yandex browsers.
This sample is a fully-weaponized delivery of PhantomStealer v3.5.0, a commercial infostealer sold as Malware-as-a-Service (MaaS) via phantomsoftwares.site and Telegram channel @Oldphantomoftheopera.
This sample is a fully-weaponized delivery of PhantomStealer v3.5.0, a commercial infostealer sold as Malware-as-a-Service (MaaS) via phantomsoftwares.site and Telegram channel @Oldphantomoftheopera.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
It ships as the final stage of a four-stage Windows dropper chain that smica83 uploaded as update.ps1 on April 21: an AES-256-CBC-wrapped PowerShell decrypts to an XOR-obfuscated PowerShell
The injector performs process hollowing on the legitimate process C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.Exe. It then allocates a memory region in the target process through `VirtualAllocEx`, inserts the PhantomStealer payload through `WriteProcessMemory`, and calls `ResumeThread`.
The injector performs process hollowing on the legitimate process C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.Exe.
This file is an “injector”-type malware that exploits vulnerable drivers to disable security software... used in a BYOVD (Bring Your Own Vulnerable Driver) attack.
The injector performs process hollowing on the legitimate process C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.Exe. It then allocates a memory region in the target process through `VirtualAllocEx`, inserts the PhantomStealer payload through `WriteProcessMemory`, and calls `ResumeThread`.
The injected PhantomStealer runs within the context of the AddInProcess32.Exe process and collects data such as keystrokes...
It also steals... login session cookies... Cookies Login session cookies stored in the browser
the final PhantomStealer payload running inside Aspnet_compiler.exe targets: ... Cryptocurrency wallet extensions ... Wireless network passwords ... System reconnaissance
The injected PhantomStealer runs within the context of the AddInProcess32.Exe process and collects data such as keystrokes...
The injected PhantomStealer runs within the context of the AddInProcess32.Exe process and collects data such as keystrokes and screen captures...
It also steals cryptocurrency wallet data and clipboard contents... Clipboard history Text copied by the user to the clipboard | It performs a “clipper” function that replaces cryptocurrency wallet addresses stored in the clipboard with the threat actor’s address.
PhantomCore automates collection of files and authentication data stored in local repositories and databases of infected hosts using PhantomStealer, XenArmor All‑In‑One Password Recovery, and Rclone
68 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
25 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Password-stealing malware distributed through an Italian malspam campaign using a payment-themed lure.
A password-stealing malware family distributed through Italian-language malspam.
Information-stealing malware injected into AddInProcess32.exe after the injector disables security tools via BYOVD. It collects keystrokes, screen captures, stored browser and application credentials, cookies, system and network information, credit card data, files, crypto wallet data, and clipboard contents, and also performs clipboard wallet-address replacement as a clipper.
Password stealer distributed via malspam campaigns targeting Italy during the week of 2026-06-15 to 2026-06-21.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.