Phantom Stealer is taking a familiar computer file and turning it into a hiding place.
The credential-stealing malware can conceal its next stage in PNG resources, then quietly collect passwords, browser cookies, cryptocurrency wallet material and other valuable data from Windows systems.
The threat has appeared in campaigns aimed at users in several countries.
Its operators use phishing emails, pirated software and malicious links circulated through Discord and Telegram, making an infection possible wherever a tempting download or message gets a click.
Analysts at Splunk identified the malware as a .NET-based stealer with a modular design that can help both less experienced and established criminals deploy it.
That flexibility raises the stakes: stolen session cookies can let an intruder enter an account without knowing the password, while wallet data can lead directly to financial loss.
Splunk said in a report shared with Cyber Security News (CSN) that the malware can stay hidden, keep access after a restart, and gather browser, wallet, file and clipboard data.
Its use of image-borne payloads also echoes recent PNG steganography campaigns, where normal-looking graphics carry code that scanners may overlook.
The PNG file is not necessarily the item that starts the infection. In one observed chain, a .NET loader stores an executable in a PNG entry within its own resources.
The concealed data is encrypted, and the loader decrypts it to reveal Phantom Stealer only after it has started, frustrating quick file inspection.
That approach is called steganography, meaning information is hidden inside an ordinary-looking file.
It is particularly useful because image files are common and often trusted. Readers may recall earlier image hiding attacks, which similarly used encrypted material disguised as PNG content.
Another loader arrived through a phishing email as a heavily obscured PowerShell script.
It decrypted code and placed it inside explorer.exe, a normal Windows process. From there, it can unpack the final stealer and weaken visibility by interfering with Windows security scanning and event logging.
The supplied research illustrates extraction of the next-stage content hidden in two image files.
The practical lesson is simple: a picture file alone is not proof of danger, but unexpected image resources paired with script activity deserve close review.
Once active, Phantom Stealer searches browser databases and configuration files for saved usernames, passwords, profiles, cookies and payment-card data.
Cookies matter because they can preserve an authenticated web session. This makes browser session theft risks a concern even for people who use multi-factor authentication.
The malware also copies data from cryptocurrency wallet browser extensions and desktop wallet applications. It watches the clipboard, looking for wallet addresses.
When it finds one, it can replace the copied address with an attacker-controlled value, potentially sending a payment to the wrong recipient when the victim pastes it.
Its reach extends beyond browsers. Researchers observed it seeking selected documents and databases, FileZilla settings, saved WinSCP credentials, Outlook profile information, screenshots, typed keystrokes and saved Wi-Fi profiles.
It can create a Registry Run entry or use the Startup folder so it launches again after reboot.
Before stealing data, it checks system, account, processes, services and network details for signs it is inside a sandbox. It can slow or halt when it suspects analysis.
This means a test result should not be treated as final, especially when a sample has not completed timing checks. It starts Chrome with command line settings to isolate work from the victim’s browser session.
Defenders should investigate unusual PowerShell activity, remote process injection, non-browser programs accessing browser data, and browsers launched with a custom user-data directory or no-sandbox setting.
Security teams should also inspect suspicious downloads and email attachments, block unauthorized software, and rotate passwords, sessions and wallet credentials after a confirmed infection.
Similar crypto wallet targeting tactics show why affected assets should be treated as exposed immediately.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| SHA-256 | b588caa5365451a6c60fd73fec5b73f13ac41bcc2a3a3bed7244df5917a62f32 | Phantom Stealer Loader; Phantom Stealer PowerShell Loader |
| SHA-256 | 382233c398cbc35dcee845ee17046815f37588a382a8106bfb9b0252ea803961 | Phantom Stealer Batch Loader |
| SHA-256 | 790945e17a51691483455a11af2efcbe15f2b473b65b151f50287623d1468516 | Phantom Stealer |
| SHA-256 | 01f1e5369aa0332abb681df7c37818e197ec0a5b5d7b81836b3369a2b1780950 | Phantom Stealer |
| SHA-256 | 10cfcad907275497dab92af0d687674cec3a0333f80dd16d8d22254794bb2d60 | Phantom Stealer |
| SHA-256 | 2d5003d9318ae85eb22de99d19705a3cd7bf8e5c3349df979dfb3bdfa080908e | Phantom Stealer |
| SHA-256 | 528a46842744366b57edfc6fe2810ca7df43900db75126cd1c78f32957143364 | Phantom Stealer |
| SHA-256 | e3ceeb24bdca8842d426e87fa61cf185d68fd7783e1a2b97d4106832ca266724 | Phantom Stealer |
| SHA-256 | f82a4d30132b5a57cbfd81c7ab0a53d0cf0dda402c2731732a0097aceb4b0b76 | Phantom Stealer |
| SHA-256 | be119a21bedc3a79bf4dea8bcf5adf18304997a01ea23e276b9c31be37b789ab | Phantom Stealer JavaScript Loader |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…