A sophisticated phishing campaign known as Operation MoneyMount-ISO has been identified targeting finance, accounting, treasury, and payment departments in Russia. Attackers use Russian-language emails impersonating financial institutions, such as TorFX Currency Broker, to deliver ZIP attachments containing malicious ISO files. When executed, these ISO files mount as virtual drives and deploy executables that load the Phantom information-stealing malware, which is capable of credential theft, invoice and payment fraud, and unauthorized fund transfers. The campaign also targets secondary sectors including procurement, legal, HR/payroll, executive assistants, and Russian-speaking SMEs, posing significant risks of lateral movement within IT systems.
Technical analysis reveals that the infection chain involves a multi-stage payload delivery, with the initial executable loading a DLL (CreativeAI.dll) that decrypts and injects the final Phantom Stealer payload into memory. The campaign demonstrates advanced social engineering and technical sophistication, leveraging fake payment confirmation lures and ISO mounting to bypass traditional security controls. Security researchers emphasize the need for heightened vigilance among Russian financial organizations and recommend monitoring for related IOCs and MITRE ATT&CK techniques associated with this threat.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Researchers disclosed that Phantom Stealer exfiltrates stolen data through redundant channels including Telegram, Discord, and FTP, and uses anti-analysis checks that can trigger self-deletion in monitored or virtualized environments. Indicators of compromise and defensive recommendations were published to help organizations detect and respond to the campaign.
Analysis showed that when victims opened the ZIP-delivered ISO image, it mounted as a virtual drive and launched executables that deployed Phantom Stealer in a multi-stage infection chain. The malware was described as stealing credentials, browser data, cryptocurrency wallet information, Discord tokens, clipboard contents, and keystrokes.
Seqrite Labs identified an active phishing campaign dubbed Operation MoneyMount-ISO targeting Russian-speaking organizations, especially finance and accounting functions. The campaign used Russian-language lures impersonating TorFX Currency Broker or payment confirmations to deliver malicious ZIP attachments containing ISO files.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourceseqrite.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.