Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Hackers Target Windows Systems Using Phantom Stealer Hidden in ISO Files

Seqrite Labs has identified an active phishing campaign originating from Russia. This campaign deploys the Phantom information-stealing malware via malicious ISO files embedded in counterfeit payment confirmation emails.

Seqrite Labs has identified an active phishing campaign originating from Russia. This campaign deploys the Phantom information-stealing malware via malicious ISO files embedded in counterfeit payment confirmation emails.

The attack targets finance and accounting professionals within Russian organizations. Social engineering tactics are employed to deceive recipients into executing malicious payloads that compromise credentials, cryptocurrency wallets, browser data, and sensitive files.

Secondary targets include procurement teams, legal departments, HR and payroll staff, executive assistants, and small to medium-sized enterprises in Russian-speaking regions.

The risks associated with this attack include credential theft, invoice fraud, unauthorized financial transfers, and potential lateral movement into broader IT systems.

According to Seqrite Researchers, the phishing emails are titled "Подтверждение банковского перевода" (Confirmation of Bank Transfer) and originate from compromised email addresses. These emails impersonate the TorFX Currency Broker and utilize formal business language to appear legitimate.

The emails contain a ZIP archive approximately 1 megabyte in size, which conceals an ISO file designed to bypass traditional security controls. The sender domain "iskra-svarka.ru" and the spoofed "agroterminal.c" domain are unrelated to the purported organization, indicating email spoofing and impersonation tactics.

Seqrite Labs has identified an active phishing campaign originating from Russia.
Paige Monroe · Thehackingpost

Upon opening the ZIP attachment and executing the ISO file, it auto-mounts as a virtual CD drive, revealing an executable disguised as a legitimate document. This executable loads additional payloads into memory, beginning with a DLL file named CreativeAI.dll that contains encrypted code. This DLL decrypts and injects the final version of the Phantom Stealer malware into the system.

The malware uses steganography techniques, hiding malicious code within System.Drawing.Bitmap objects to evade detection. This approach allows attackers to bypass security solutions that primarily scan for known malware signatures.

The campaign, termed Operation MoneyMount-ISO, reflects a growing trend where threat actors leverage ISO-mounted executables to deploy commodity stealers while evading perimeter security controls. The use of payment-confirmation social engineering lures and spoofed Russian business domains indicates a highly targeted credential-theft activity aimed at finance-related roles.

The increasing sophistication of stealer malware delivered via unconventional file formats necessitates a multi-layered defense strategy that combines technical controls with user education.

Advertisement

27bc3c4eed4e70ff5a438815b1694f83150c36d351ae1095c2811c962591e1bf Email

4b16604768565571f692d3fa84bda41ad8e244f95fbe6ab37b62291c5f9b3599 Подтверждение банковского перевода.zip

60994115258335b1e380002c7efcbb47682f644cb6a41585a1737b136e7544f9 Подтверждение банковского перевода.iso

78826700c53185405a0a3897848ca8474920804a01172f987a18bd3ef9a4fc77 HvNC.exe

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories