Skip to content

PhantomStealer

PhantomStealer is a Windows C#/.NET information stealer, including version 3.5.0 builds marketed through a malware-as-a-service ecosystem.

Profile source: Mallory opens in a new tab

PhantomStealer

Family profile

PhantomStealer is a Windows C#/.NET information stealer, including version 3.5.0 builds marketed through a malware-as-a-service ecosystem. It has been deployed in phishing and malspam campaigns using business-oriented invoice, quotation, order, shipping, and procurement lures, with observed targeting of Italian organizations as well as maritime, industrial supply-chain, procurement, and accounts-receivable personnel. Campaigns commonly use heavily obfuscated JavaScript or JScript droppers that invoke PowerShell, decrypt and reflectively load .NET stages in memory, and inject the final payload into legitimate .NET processes through process hollowing. Some deployments also use a vulnerable-driver-based injector to disable endpoint security products before launching the stealer.

PhantomStealer harvests stored browser credentials, cookies, autofill and payment-card data from Chromium- and Gecko-based browsers; it also collects browser-extension and desktop cryptocurrency-wallet data, email-client profiles, FTP and remote-access client credentials, messaging artifacts, saved Wi-Fi credentials, clipboard content, selected local files, and host and network information. Builds may support keylogging and screenshot capture. Its crypto-clipper module can replace copied cryptocurrency wallet addresses with operator-controlled addresses. Collected data has been exfiltrated through SMTP, FTP, or the Telegram Bot API, depending on build configuration.

The malware includes configurable persistence, anti-analysis, and self-deletion functionality, though these features are disabled in some observed builds. Persistence mechanisms include startup shortcuts, Registry Run entries, and monitoring intended to relaunch terminated payloads. PhantomStealer is associated with the PhantomCore actorโ€™s tooling ecosystem and has also been linked to a commercially promoted PhantomStealer MaaS operation.

Capabilities

  • Credential Theft
  • Crypto Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Process Injection
  • Reconnaissance
  • Session Hijacking

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 26, 2026
Last activity
Sep 2, 2026
Feed role
C2 / Distribution
Host form
70 IP / 51 hostnames

Leading locations

  • US32
  • DE15
  • CN13
  • HK10
  • NL9
  • LU4
  • SG4
  • KR3
  • GB2
  • IN2
  • IR2
  • RO2

Leading providers

  • Cloudflare, Inc.8
  • CTG Server Limited7
  • FEMO IT SOLUTIONS LIMITED7
  • HostPapa6
  • Omegatech LTD5
  • CHINA UNICOM China169 Backbone4

Infrastructure traits

  • Hosting 97
  • Anycast 9

Samples

Recent associated samples

Reported operators

Threat actors

3 named in public reporting
PhantomCore

PhantomCore uses its in-house infostealer, PhantomStealer, to export, decrypt, and save as an archive the authentication data stored on the infected host in Chrome and Yandex browsers.

Sandworm

This sample is a fully-weaponized delivery of PhantomStealer v3.5.0, a commercial infostealer sold as Malware-as-a-Service (MaaS) via phantomsoftwares.site and Telegram channel @Oldphantomoftheopera.

Oldphantomoftheopera

This sample is a fully-weaponized delivery of PhantomStealer v3.5.0, a commercial infostealer sold as Malware-as-a-Service (MaaS) via phantomsoftwares.site and Telegram channel @Oldphantomoftheopera.

MITRE ATT&CK

PhantomStealer in ATT&CK

49 distinct techniques

Techniques

49 techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.