Hackers Target Windows Systems Using Phantom Stealer Hidden in ISO Files
Seqrite Labs has identified an active phishing campaign originating from Russia. This campaign deploys the Phantom information-stealing malware via malicious ISO files embedded in counterfeit payment confirmation emails.
Seqrite Labs has identified an active phishing campaign originating from Russia. This campaign deploys the Phantom information-stealing malware via malicious ISO files embedded in counterfeit payment confirmation emails.
The attack targets finance and accounting professionals within Russian organizations. Social engineering tactics are employed to deceive recipients into executing malicious payloads that compromise credentials, cryptocurrency wallets, browser data, and sensitive files.
Secondary targets include procurement teams, legal departments, HR and payroll staff, executive assistants, and small to medium-sized enterprises in Russian-speaking regions.
The risks associated with this attack include credential theft, invoice fraud, unauthorized financial transfers, and potential lateral movement into broader IT systems.
According to Seqrite Researchers, the phishing emails are titled "Подтверждение банковского перевода" (Confirmation of Bank Transfer) and originate from compromised email addresses. These emails impersonate the TorFX Currency Broker and utilize formal business language to appear legitimate.
The emails contain a ZIP archive approximately 1 megabyte in size, which conceals an ISO file designed to bypass traditional security controls. The sender domain "iskra-svarka.ru" and the spoofed "agroterminal.c" domain are unrelated to the purported organization, indicating email spoofing and impersonation tactics.
Seqrite Labs has identified an active phishing campaign originating from Russia.
Upon opening the ZIP attachment and executing the ISO file, it auto-mounts as a virtual CD drive, revealing an executable disguised as a legitimate document. This executable loads additional payloads into memory, beginning with a DLL file named CreativeAI.dll that contains encrypted code. This DLL decrypts and injects the final version of the Phantom Stealer malware into the system.
The malware uses steganography techniques, hiding malicious code within System.Drawing.Bitmap objects to evade detection. This approach allows attackers to bypass security solutions that primarily scan for known malware signatures.
The campaign, termed Operation MoneyMount-ISO, reflects a growing trend where threat actors leverage ISO-mounted executables to deploy commodity stealers while evading perimeter security controls. The use of payment-confirmation social engineering lures and spoofed Russian business domains indicates a highly targeted credential-theft activity aimed at finance-related roles.
The increasing sophistication of stealer malware delivered via unconventional file formats necessitates a multi-layered defense strategy that combines technical controls with user education.
27bc3c4eed4e70ff5a438815b1694f83150c36d351ae1095c2811c962591e1bf Email
4b16604768565571f692d3fa84bda41ad8e244f95fbe6ab37b62291c5f9b3599 Подтверждение банковского перевода.zip
60994115258335b1e380002c7efcbb47682f644cb6a41585a1737b136e7544f9 Подтверждение банковского перевода.iso
78826700c53185405a0a3897848ca8474920804a01172f987a18bd3ef9a4fc77 HvNC.exe
Based on reporting by GBHackers.
