Proofpoint and Splunk report renewed activity tied to Phantom Stealer, a Windows infostealer linked to the broader Stealerium malware family, as threat actors expand phishing and malicious-download campaigns aimed at harvesting identities and credentials. Proofpoint observed campaigns attributed to TA2715 and TA2536 using lures themed around payments, court summons, donations, travel, hospitality, and adult content, delivered through compressed executables, JavaScript, VBScript, ISO/IMG, and ACE attachments. The malware family, derived from an open-source .NET codebase, has proliferated into overlapping variants including Phantom and Warp Stealer.
Once executed, Phantom Stealer collects browser credentials, cookies, autofill data, session tokens, FTP and SSH client secrets, email client data, VPN configurations, cryptocurrency wallet information, and other files from compromised Windows systems. Reported behaviors include application enumeration, access to browser SQLite stores such as Login Data, Cookies, and Web Data, unauthorized reads of WinSCP configuration folders, registry run key or scheduled-task persistence, Wi-Fi reconnaissance, PowerShell-based Windows Defender exclusions, and in some variants abuse of Chrome remote debugging to bypass browser protections and steal active sessions. Stolen data has been archived and exfiltrated through encrypted channels and services including SMTP, Discord webhooks, Telegram, and GoFile, increasing the risk of account takeover, fraud, and follow-on enterprise compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Splunk documented Phantom Stealer as an infostealer targeting browser data, FTP and SSH clients, email clients, cryptocurrency wallets, and VPN configurations, and highlighted behavioral detections such as browser database access, WinSCP folder reads, and registry run key persistence.
Proofpoint observed renewed Stealerium activity beginning in May 2025, including campaigns it attributed to TA2715 and TA2536 using varied phishing lures and attachment types.
Proofpoint reports that Stealerium had only limited presence in its email threat telemetry beginning in early 2023 before later activity increased.
Proofpoint says the open-source .NET infostealer Stealerium appeared on GitHub in 2022, after which multiple closely related variants proliferated, including Phantom Stealer and Warp Stealer.
Proofpoint published new technical details on Stealerium-linked campaigns, including post-execution Wi-Fi reconnaissance, Defender exclusion changes, scheduled-task persistence, Chrome remote debugging abuse, and multiple exfiltration channels.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.