A sophisticated phishing campaign known as Operation MoneyMount-ISO has been identified targeting finance, accounting, treasury, and payment departments in Russia. Attackers use Russian-language emails impersonating financial institutions, such as TorFX Currency Broker, to deliver ZIP attachments containing malicious ISO files. When executed, these ISO files mount as virtual drives and deploy executables that load the Phantom information-stealing malware, which is capable of credential theft, invoice and payment fraud, and unauthorized fund transfers. The campaign also targets secondary sectors including procurement, legal, HR/payroll, executive assistants, and Russian-speaking SMEs, posing significant risks of lateral movement within IT systems.
Technical analysis reveals that the infection chain involves a multi-stage payload delivery, with the initial executable loading a DLL (CreativeAI.dll) that decrypts and injects the final Phantom Stealer payload into memory. The campaign demonstrates advanced social engineering and technical sophistication, leveraging fake payment confirmation lures and ISO mounting to bypass traditional security controls. Security researchers emphasize the need for heightened vigilance among Russian financial organizations and recommend monitoring for related IOCs and MITRE ATT&CK techniques associated with this threat.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Researchers disclosed that Phantom Stealer exfiltrates stolen data through redundant channels including Telegram, Discord, and FTP, and uses anti-analysis checks that can trigger self-deletion in monitored or virtualized environments. Indicators of compromise and defensive recommendations were published to help organizations detect and respond to the campaign.
Analysis showed that when victims opened the ZIP-delivered ISO image, it mounted as a virtual drive and launched executables that deployed Phantom Stealer in a multi-stage infection chain. The malware was described as stealing credentials, browser data, cryptocurrency wallet information, Discord tokens, clipboard contents, and keystrokes.
Seqrite Labs identified an active phishing campaign dubbed Operation MoneyMount-ISO targeting Russian-speaking organizations, especially finance and accounting functions. The campaign used Russian-language lures impersonating TorFX Currency Broker or payment confirmations to deliver malicious ZIP attachments containing ISO files.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourceseqrite.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.