PhantomStealer is a Windows-focused .NET information stealer sold and deployed through a Malware-as-a-Service ecosystem and also used by the PhantomCore intrusion set as an in-house credential theft tool. It has been observed in active phishing and malspam campaigns using business-themed lures such as invoices, requests for quotation, payments, orders, documents, and quote-review requests, often delivered through heavily obfuscated JavaScript or JScript droppers and multi-stage PowerShell loaders. Multiple campaigns used reflective loading and process hollowing into legitimate .NET utilities such as Aspnet_compiler.exe or AddInProcess32.exe to evade detection, and some delivery chains employed bring-your-own-vulnerable-driver techniques to terminate security products before launching the stealer.
PhantomStealer is best characterized as an infostealer with broad credential and data theft coverage. Observed capabilities include theft of saved passwords, cookies, autofill data, credit card data, browser wallet data, desktop cryptocurrency wallet data, Outlook and other email client data, FTP client credentials, Wi-Fi passwords, clipboard contents, files of interest, and host reconnaissance data. Some variants also implement keylogging, screenshot capture, and cryptocurrency clipper functionality that replaces copied wallet addresses in the clipboard. PhantomStealer has been documented targeting Chromium- and Gecko-based browsers, messaging and mail artifacts, cryptocurrency wallet extensions and desktop wallets, and general system and network information.
Exfiltration methods vary by build and operator configuration. Documented samples have sent stolen data through the Telegram Bot API, SMTP, or FTP, with different modules enabled or disabled per campaign. Several analyzed builds showed per-sample customization consistent with an automated builder, including unique XOR keys, obfuscated class names, GUID-like resource identifiers, and encrypted configuration blobs. Version 3.5.0 has been repeatedly observed in 2026 campaigns and supports modular features such as anti-analysis checks, startup persistence, file grabbing, screenshots, keylogging, and clipper behavior, though not all modules are enabled in every deployment.
PhantomStealer has been associated with the PhantomStealer MaaS branding linked to the alias Oldphantomoftheopera and with infrastructure overlap suggesting multi-operator deployment. Separately, PhantomCore has used PhantomStealer during post-compromise collection to export, decrypt, and archive browser authentication data from infected Windows hosts. Targeting has included business users in procurement, shipping, finance, and supply-chain roles, as well as organizations in maritime and industrial sectors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
PhantomCore uses its in-house infostealer, PhantomStealer, to export, decrypt, and save as an archive the authentication data stored on the infected host in Chrome and Yandex browsers.
This sample is a fully-weaponized delivery of PhantomStealer v3.5.0, a commercial infostealer sold as Malware-as-a-Service (MaaS) via phantomsoftwares.site and Telegram channel @Oldphantomoftheopera.
This sample is a fully-weaponized delivery of PhantomStealer v3.5.0, a commercial infostealer sold as Malware-as-a-Service (MaaS) via phantomsoftwares.site and Telegram channel @Oldphantomoftheopera.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK TTPs ID Technique Implementation T1078 Valid Accounts Abuses compromised mail credentials
It ships as the final stage of a four-stage Windows dropper chain that smica83 uploaded as update.ps1 on April 21: an AES-256-CBC-wrapped PowerShell decrypts to an XOR-obfuscated PowerShell
The injector performs process hollowing on the legitimate process C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.Exe. It then allocates a memory region in the target process through `VirtualAllocEx`, inserts the PhantomStealer payload through `WriteProcessMemory`, and calls `ResumeThread`.
The injector performs process hollowing on the legitimate process C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.Exe.
This file is an “injector”-type malware that exploits vulnerable drivers to disable security software... used in a BYOVD (Bring Your Own Vulnerable Driver) attack.
MITRE ATT&CK TTPs ID Technique Implementation T1078 Valid Accounts Abuses compromised mail credentials
The injector performs process hollowing on the legitimate process C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.Exe. It then allocates a memory region in the target process through `VirtualAllocEx`, inserts the PhantomStealer payload through `WriteProcessMemory`, and calls `ResumeThread`.
The injector performs process hollowing on the legitimate process C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.Exe.
The injected PhantomStealer runs within the context of the AddInProcess32.Exe process and collects data such as keystrokes...
It also steals... login session cookies... Cookies Login session cookies stored in the browser
the final PhantomStealer payload running inside Aspnet_compiler.exe targets: ... Cryptocurrency wallet extensions ... Wireless network passwords ... System reconnaissance
The injected PhantomStealer runs within the context of the AddInProcess32.Exe process and collects data such as keystrokes...
The injected PhantomStealer runs within the context of the AddInProcess32.Exe process and collects data such as keystrokes and screen captures...
It also steals cryptocurrency wallet data and clipboard contents... Clipboard history Text copied by the user to the clipboard | It performs a “clipper” function that replaces cryptocurrency wallet addresses stored in the clipboard with the threat actor’s address.
PhantomCore automates collection of files and authentication data stored in local repositories and databases of infected hosts using PhantomStealer, XenArmor All‑In‑One Password Recovery, and Rclone
68 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Information-stealing malware injected into AddInProcess32.exe after the injector disables security tools via BYOVD. It collects keystrokes, screen captures, stored browser and application credentials, cookies, system and network information, credit card data, files, crypto wallet data, and clipboard contents, and also performs clipboard wallet-address replacement as a clipper.
Password stealer distributed via malspam campaigns targeting Italy during the week of 2026-06-15 to 2026-06-21.
A password-stealing malware family distributed via malspam campaigns targeting Italy, observed in email themes such as requests.
A password stealer family observed in malspam campaigns targeting Italy during the week of 2026-06-01 to 2026-06-07.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.