New Phantom Stealer Campaign Hits Windows Machines Through ISO Mounting
Researchers have identified a phishing campaign originating in Russia that utilizes the Phantom information-stealing malware through malicious ISO files.
Researchers have identified a phishing campaign originating in Russia that utilizes the Phantom information-stealing malware through malicious ISO files.
The operation, referred to as "Operation MoneyMount-ISO," specifically targets finance and accounting departments by using fake payment confirmation emails to induce recipients to execute the malware payload.
The campaign primarily targets finance, accounting, treasury, and payment departments in Russia. Secondary targets include procurement, legal, HR/payroll teams, executive assistants, and Russian-speaking small and medium enterprises.
The attack involves significant risks such as credential theft, fraud in invoices and payments, unauthorized fund transfers, and lateral movement into IT systems.
The infection is initiated via a phishing email in Russian titled "Подтверждение банковского перевода" (Confirmation of Bank Transfer) sent from compromised domains. The email impersonates TorFX Currency Broker and contains a ZIP attachment approximately 1 MB in size. Opening the ZIP file reveals a malicious ISO file disguised as a legitimate bank transfer confirmation document.
When executed, the ISO file auto-mounts as a virtual CD drive, displaying an executable file that appears legitimate. This executable loads additional payloads into memory, including a DLL named CreativeAI.dll containing encrypted code.
The DLL decrypts and injects the final version of the Phantom Stealer malware into the system.
Researchers have identified a phishing campaign originating in Russia that utilizes the Phantom information-stealing malware through malicious ISO files.
Phantom Stealer is a comprehensive data theft tool with extensive capabilities. It features anti-analysis techniques that detect virtualized environments and security tools, and it automatically self-destructs if discovered.
According to Seqrite , the malware harvests data from cryptocurrency wallets, both from browser extensions and desktop applications, targeting numerous known crypto wallets.
The stealer extracts Discord authentication tokens from browser databases and native Discord installations, validates them through Discord’s API, and collects user information, including usernames, emails, and Nitro subscription status.
Additional capabilities include a global keystroke logger using low-level Windows hooks, recovery of saved passwords and credit card data from Chromium-based browsers via SQLite database parsing, and targeted file collection based on predefined criteria.
Once collected, the stolen data is packaged into a ZIP archive that includes system metadata, public IP addresses, and configuration toggles.
The malware employs multiple exfiltration channels, including Telegram bot APIs, Discord webhooks, and FTP servers with optional SSL support, ensuring the attackers receive the stolen information through redundant communication methods.
Organizations should consider implementing continuous filtering of containerized attachments, deploying memory-behavior monitoring solutions, and hardening email security workflows for finance-facing departments to defend against these evolving threats.
27bc3c4eed4e70ff5a438815b1694f83150c36d351ae1095c2811c962591e1bf Email
4b16604768565571f692d3fa84bda41ad8e244f95fbe6ab37b62291c5f9b3599 Подтверждение банковского перевода.zip
60994115258335b1e380002c7efcbb47682f644cb6a41585a1737b136e7544f9 Подтверждение банковского перевода.iso
78826700c53185405a0a3897848ca8474920804a01172f987a18bd3ef9a4fc77 HvNC.exe
Based on reporting by Cyber Security News.
