Last seven days
- First activity
- Aug 26, 2026
- Last activity
- Sep 2, 2026
- Feed role
- C2 / Distribution
- Host form
- 70 IP / 51 hostnames
PhantomStealer is a Windows C#/.NET information stealer, including version 3.5.0 builds marketed through a malware-as-a-service ecosystem.
Profile source: Mallory opens in a new tabPhantomStealer
PhantomStealer is a Windows C#/.NET information stealer, including version 3.5.0 builds marketed through a malware-as-a-service ecosystem. It has been deployed in phishing and malspam campaigns using business-oriented invoice, quotation, order, shipping, and procurement lures, with observed targeting of Italian organizations as well as maritime, industrial supply-chain, procurement, and accounts-receivable personnel. Campaigns commonly use heavily obfuscated JavaScript or JScript droppers that invoke PowerShell, decrypt and reflectively load .NET stages in memory, and inject the final payload into legitimate .NET processes through process hollowing. Some deployments also use a vulnerable-driver-based injector to disable endpoint security products before launching the stealer.
PhantomStealer harvests stored browser credentials, cookies, autofill and payment-card data from Chromium- and Gecko-based browsers; it also collects browser-extension and desktop cryptocurrency-wallet data, email-client profiles, FTP and remote-access client credentials, messaging artifacts, saved Wi-Fi credentials, clipboard content, selected local files, and host and network information. Builds may support keylogging and screenshot capture. Its crypto-clipper module can replace copied cryptocurrency wallet addresses with operator-controlled addresses. Collected data has been exfiltrated through SMTP, FTP, or the Telegram Bot API, depending on build configuration.
The malware includes configurable persistence, anti-analysis, and self-deletion functionality, though these features are disabled in some observed builds. Persistence mechanisms include startup shortcuts, Registry Run entries, and monitoring intended to relaunch terminated payloads. PhantomStealer is associated with the PhantomCore actorโs tooling ecosystem and has also been linked to a commercially promoted PhantomStealer MaaS operation.
C2 tracking
Derp observations, rolling seven-day window
Samples
1b723594e574c00aac2c946ff738a0454f7c24f6ebc84ae45a6af9628b08cb96 2b20eb4237ad2eab05c4a2ad261bcfd436663cf32e2a45526e17dfd3a51a095d 2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 508e710d673802a532798e7dffa3aefcfb36eff0acef1620b8614917ac62e53e 8d793a16bf2e7153df21e2ede4b0baf6e080596073b27ecbeac6613b6a68b8d8 3c6126417211aacd1bb0ebadcd474747890e8930a4684ccabe448d1390b3c064 78cf8d71ec2451e820a7260f79e1bad47db041c004690668e11c05b1c7d764d3 86169823504bfb77ddf5e199fa2c683db27fcf06bf4f385f114e48e089120986 c391c8763b10b0a558f274e9553624edf70212b4658527fc7af97e0bed249254 d9f8bfbb716f94e359f88cbe21d23f7d48cd7a24cadf71207e5a2eafbb91cf4b Reported operators
PhantomCore uses its in-house infostealer, PhantomStealer, to export, decrypt, and save as an archive the authentication data stored on the infected host in Chrome and Yandex browsers.
This sample is a fully-weaponized delivery of PhantomStealer v3.5.0, a commercial infostealer sold as Malware-as-a-Service (MaaS) via phantomsoftwares.site and Telegram channel @Oldphantomoftheopera.
This sample is a fully-weaponized delivery of PhantomStealer v3.5.0, a commercial infostealer sold as Malware-as-a-Service (MaaS) via phantomsoftwares.site and Telegram channel @Oldphantomoftheopera.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.