Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Phantom Stealer Attacking Users to Steal Sensitive Data like Passwords, Browser Cookies, Credit Card Data

Phantom Stealer version 3.5 represents a significant cybersecurity threat, capable of extracting sensitive data such as passwords, browser cookies, credit card information, and cryptocurrency wallet details.

Phantom Stealer version 3.5 represents a significant cybersecurity threat, capable of extracting sensitive data such as passwords, browser cookies, credit card information, and cryptocurrency wallet details.

This malware is often disguised as legitimate software, such as Adobe installers, complicating detection before the system is compromised.

The malware initiates with an installer file, first identified on Mon, Oct 29, 2025, masquerading as an Adobe 11.7.7 installer. It is an obfuscated XML document containing embedded JavaScript to trigger malicious activities.

Upon execution, the file downloads a PowerShell script from a remote server, facilitating further system compromise and data collection. The script operates with hidden attributes, bypassing security measures.

The malware employs RC4 encryption to hide data, which, when decrypted, reveals instructions for loading a .NET assembly into memory.

The second phase includes the BLACKHAWK.dll injector, which uses process injection into the legitimate Windows utility Aspnetcompiler.exe, allowing the malware to operate undetected.

This malware is often disguised as legitimate software, such as Adobe installers, complicating detection before the system is compromised.
Megan Forbes · Thehackingpost

The malware monitors Aspnetcompiler.exe at five-second intervals to ensure continued operation.

Process Injection and Evasion Techniques

Phantom Stealer employs advanced evasion techniques, including anti-analysis checks for virtual machines, sandboxes, and monitoring tools, using a hardcoded list of sandbox usernames.

If such environments are detected, the malware self-destructs by creating a batch file to terminate its process.

The stealer utilizes Heavens Gate, a technique allowing 32-bit processes to execute in 64-bit mode, bypassing security hooks and accessing sensitive data.

Advertisement

Once installed, the malware extracts browser credentials by decrypting encrypted databases. It also collects cryptocurrency wallet credentials, email configurations, keylogged data, and system information.

Data exfiltration is achieved through multiple channels, including SMTP and FTP protocols, as well as platforms like Telegram and Discord. Stolen data is organized with computer names and timestamps for malicious use.

Organizations are advised to implement robust email filtering, regular software updates, and advanced endpoint protection to mitigate this threat.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories