Skip to content

PhantomStealer

PhantomStealer is a C#/.NET information stealer and commercially distributed Malware-as-a-Service (MaaS) family active since at least February 2026, though malspam reporting references campaigns using the name in 2025.

Profile source: Mallory opens in a new tab

PhantomStealer

Family profile

PhantomStealer is a C#/.NET information stealer and commercially distributed Malware-as-a-Service (MaaS) family active since at least February 2026, though malspam reporting references campaigns using the name in 2025. It is repeatedly described as a password stealer/infostealer and has been observed in phishing and malspam campaigns using business-themed lures such as payments, receipts, requests, quotations, invoices, documents, orders, offers, and RFQs, including campaigns targeting Italy as well as procurement, shipping, and supply-chain personnel.

Observed delivery chains commonly begin with heavily obfuscated JavaScript/JScript attachments executed by Windows Script Host, which drop or decode PowerShell stages, use custom rotational XOR decryption, load .NET assemblies reflectively, and inject the final payload into C:\Windows\Microsoft.NET\Framework\v4.0.30319\Aspnet_compiler.exe via process hollowing. Shared loader/injector components include DEV.DOWN/DEV.dll and, in another observed chain, ALTERNATE.EXECUTE. Samples have used temporary PowerShell files under C:\Temp\ and anti-analysis measures such as obfuscation, sandbox/process checks, anti-debugging logic, and in some builds self-deletion or disabled anti-analysis features.

Capabilities directly described in the content include theft of saved passwords, cookies, autofill data, and credit card data from Chromium- and Gecko-based browsers; theft of Outlook, Thunderbird, FoxMail, Telegram, Discord token, WinSCP, FileZilla, and Wi-Fi credential data; theft of cryptocurrency wallet data from desktop wallets and numerous browser wallet extensions; collection of selected local files; and system reconnaissance such as processor information and external IP address. One report on PhantomCore states PhantomStealer exports, decrypts, and archives authentication data stored in Chrome and Yandex browsers. Some PhantomStealer v3.5.0 builds also include a crypto-clipper that replaces clipboard wallet addresses for cryptocurrencies including BTC, ETH, LTC, BCH, TRX, SOL, and in one report XMR.

Exfiltration mechanisms vary by build. Observed samples exfiltrated via the Telegram Bot API, SMTP, or FTP. Reported SMTP infrastructure included compromised legitimate mail servers mail.kluangstation.com.my and mail.tms.cl, with receiver addresses ike@graceishere.tech and info@graceishere.tech. A recovered FTP-configured v3.5.0 sample used ftp.corella.ro with account backup@corella.ro. Some analyzed v3.5.0 builds had Telegram, Discord, FTP, startup persistence, keylogging, screenshots, anti-analysis, or file-grabber modules disabled in configuration. Reported mutexes include ZK5BJ6U4KNLQT3D9UGJZ, EMSMNP0JM2FCVRK21CDD, and 6WWCTAOSPN0K7LMSCS01.

PhantomStealer is linked in the content to the PhantomStealer MaaS ecosystem branded through phantomsoftwares.site and the Telegram identity/channel @Oldphantomoftheopera / Oldphantomoftheopera. Infrastructure overlap between phantomsoftwares.site and graceishere.tech is explicitly noted. Separately, PhantomStealer is also described as an in-house infostealer used by the PhantomCore threat actor, which uses it to collect and archive browser authentication data and as part of broader intrusion activity involving phishing, persistence, lateral movement, and exfiltration.

High-confidence indicators mentioned in the content include phantomsoftwares.site, graceishere.tech, mail.kluangstation.com.my, mail.tms.cl, ftp.corella.ro, the DEV.DOWN injector DLL SHA256 195e3d859d8fa9d0c12cd38beef8898e307b71422c8a18c2c3648f5f0220b447, PhantomStealer payload SHA256 values including 7df24c505edbfd1bdee879f8fc12e7b67590755513f28cadadcfd173da07d14d and 6eb33e137719e0261e910379786355f85da25b73c119616d34b3119da81f7ff0, and lure filenames such as Invoice 10225.js and RFQ108004 - EDS International.js.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 2, 2026
Last activity
Aug 9, 2026
Feed role
C2 / Distribution
Host form
4 IP / 18 hostnames

Leading locations

  • US10
  • FR3
  • SG2
  • ES1
  • HK1
  • IN1
  • LU1
  • MY1
  • NL1
  • TR1

Leading providers

  • Cloudflare, Inc.4
  • Stellar Group SAS2
  • AXARNET COMUNICACIONES, S.L.1
  • BlueVPS OU1
  • DEFT.COM1
  • Dreamscape Networks Limited1

Infrastructure traits

  • Hosting 22
  • Anycast 4

Samples

Recent associated samples

Reported operators

Threat actors

3 named in public reporting
PhantomCore

PhantomCore uses its in-house infostealer, PhantomStealer, to export, decrypt, and save as an archive the authentication data stored on the infected host in Chrome and Yandex browsers.

Sandworm

This sample is a fully-weaponized delivery of PhantomStealer v3.5.0, a commercial infostealer sold as Malware-as-a-Service (MaaS) via phantomsoftwares.site and Telegram channel @Oldphantomoftheopera.

Oldphantomoftheopera

This sample is a fully-weaponized delivery of PhantomStealer v3.5.0, a commercial infostealer sold as Malware-as-a-Service (MaaS) via phantomsoftwares.site and Telegram channel @Oldphantomoftheopera.

MITRE ATT&CK

PhantomStealer in ATT&CK

41 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.