Last seven days
- First activity
- Aug 2, 2026
- Last activity
- Aug 9, 2026
- Feed role
- C2 / Distribution
- Host form
- 4 IP / 18 hostnames
PhantomStealer is a C#/.NET information stealer and commercially distributed Malware-as-a-Service (MaaS) family active since at least February 2026, though malspam reporting references campaigns using the name in 2025.
Profile source: Mallory opens in a new tabPhantomStealer
PhantomStealer is a C#/.NET information stealer and commercially distributed Malware-as-a-Service (MaaS) family active since at least February 2026, though malspam reporting references campaigns using the name in 2025. It is repeatedly described as a password stealer/infostealer and has been observed in phishing and malspam campaigns using business-themed lures such as payments, receipts, requests, quotations, invoices, documents, orders, offers, and RFQs, including campaigns targeting Italy as well as procurement, shipping, and supply-chain personnel.
Observed delivery chains commonly begin with heavily obfuscated JavaScript/JScript attachments executed by Windows Script Host, which drop or decode PowerShell stages, use custom rotational XOR decryption, load .NET assemblies reflectively, and inject the final payload into C:\Windows\Microsoft.NET\Framework\v4.0.30319\Aspnet_compiler.exe via process hollowing. Shared loader/injector components include DEV.DOWN/DEV.dll and, in another observed chain, ALTERNATE.EXECUTE. Samples have used temporary PowerShell files under C:\Temp\ and anti-analysis measures such as obfuscation, sandbox/process checks, anti-debugging logic, and in some builds self-deletion or disabled anti-analysis features.
Capabilities directly described in the content include theft of saved passwords, cookies, autofill data, and credit card data from Chromium- and Gecko-based browsers; theft of Outlook, Thunderbird, FoxMail, Telegram, Discord token, WinSCP, FileZilla, and Wi-Fi credential data; theft of cryptocurrency wallet data from desktop wallets and numerous browser wallet extensions; collection of selected local files; and system reconnaissance such as processor information and external IP address. One report on PhantomCore states PhantomStealer exports, decrypts, and archives authentication data stored in Chrome and Yandex browsers. Some PhantomStealer v3.5.0 builds also include a crypto-clipper that replaces clipboard wallet addresses for cryptocurrencies including BTC, ETH, LTC, BCH, TRX, SOL, and in one report XMR.
Exfiltration mechanisms vary by build. Observed samples exfiltrated via the Telegram Bot API, SMTP, or FTP. Reported SMTP infrastructure included compromised legitimate mail servers mail.kluangstation.com.my and mail.tms.cl, with receiver addresses ike@graceishere.tech and info@graceishere.tech. A recovered FTP-configured v3.5.0 sample used ftp.corella.ro with account backup@corella.ro. Some analyzed v3.5.0 builds had Telegram, Discord, FTP, startup persistence, keylogging, screenshots, anti-analysis, or file-grabber modules disabled in configuration. Reported mutexes include ZK5BJ6U4KNLQT3D9UGJZ, EMSMNP0JM2FCVRK21CDD, and 6WWCTAOSPN0K7LMSCS01.
PhantomStealer is linked in the content to the PhantomStealer MaaS ecosystem branded through phantomsoftwares.site and the Telegram identity/channel @Oldphantomoftheopera / Oldphantomoftheopera. Infrastructure overlap between phantomsoftwares.site and graceishere.tech is explicitly noted. Separately, PhantomStealer is also described as an in-house infostealer used by the PhantomCore threat actor, which uses it to collect and archive browser authentication data and as part of broader intrusion activity involving phishing, persistence, lateral movement, and exfiltration.
High-confidence indicators mentioned in the content include phantomsoftwares.site, graceishere.tech, mail.kluangstation.com.my, mail.tms.cl, ftp.corella.ro, the DEV.DOWN injector DLL SHA256 195e3d859d8fa9d0c12cd38beef8898e307b71422c8a18c2c3648f5f0220b447, PhantomStealer payload SHA256 values including 7df24c505edbfd1bdee879f8fc12e7b67590755513f28cadadcfd173da07d14d and 6eb33e137719e0261e910379786355f85da25b73c119616d34b3119da81f7ff0, and lure filenames such as Invoice 10225.js and RFQ108004 - EDS International.js.
C2 tracking
Derp observations, rolling seven-day window
Samples
06d7286fe48d9ab8724fdd4049e62d9fc525a5ce3898a9df6ca6afe27dbbd2b5 0a71bbd1903835fcbcb323179b460238184a4b406a3f3eab7341b0b003a26b6a 450b6c8ffce56ab8cb90010bdcfd25b20433ab6a2383785090d300b1f352bd9f 60b6d33f3c8e7321b712489c201910042b3f082e93ecba0fabb25ec1718c706b 6d79fb54a71dc3d3898ffd1c658857caa66b140da452dd7e0548237000f831be 1060e2c174b39c21614f8d8ad5ef0828905cb6102a7d5f6d6a1b2de44a32cf9d 5d5cd70cf760b62aa3eb044cd0e9d0a9d70bedf9c277fc26eced2915a18087f3 5d9709d9df3105a401b0ba476bc582951883dfd0da0cdfef2bc7070a451ef29d 83f653791490f197bfee667c341c853224fc297c54df067e51dca1a1d4126826 e2f9eeae126236bb235433322d5bccdfd605ec08607c8b367fb63da3aec7fa0d Reported operators
PhantomCore uses its in-house infostealer, PhantomStealer, to export, decrypt, and save as an archive the authentication data stored on the infected host in Chrome and Yandex browsers.
This sample is a fully-weaponized delivery of PhantomStealer v3.5.0, a commercial infostealer sold as Malware-as-a-Service (MaaS) via phantomsoftwares.site and Telegram channel @Oldphantomoftheopera.
This sample is a fully-weaponized delivery of PhantomStealer v3.5.0, a commercial infostealer sold as Malware-as-a-Service (MaaS) via phantomsoftwares.site and Telegram channel @Oldphantomoftheopera.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.