Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Abusing Trusted Business Workflows: A Multi-Stage Phantom Stealer Campaign

0
Medium
Published: 07/22/2026 (07/22/2026, 15:17:48 UTC)
Source: AlienVault OTX General

Description

This threat describes a sophisticated phishing campaign distributing Phantom Stealer v3.5.0 by impersonating trusted business entities such as UPS and the Malaysian Inland Revenue Board. The attack uses compressed archives containing malicious JavaScript that triggers obfuscated PowerShell scripts running entirely in memory. These scripts deploy multiple encrypted and encoded payload stages using Base64, AES, and XOR to evade detection. The final payload steals credentials from browsers, cryptocurrency wallets, messaging apps, and system information, exfiltrating data via SMTP with STARTTLS encryption. The campaign employs reflective code loading and process injection into legitimate binaries to reduce on-disk footprint and evade traditional defenses. The campaign is targeted notably at Malaysia. No known exploits in the wild or patches are indicated.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/22/2026, 22:26:17 UTC

Technical Analysis

A multi-stage phishing campaign impersonates legitimate business entities to deliver Phantom Stealer v3.5.0. Initial infection vectors are emails with compressed archives containing malicious JavaScript files. Execution of these files launches obfuscated PowerShell scripts that operate solely in memory, deploying encrypted and encoded payloads through Base64 encoding, AES encryption, and XOR ciphering. The final payload harvests sensitive credentials and system information before exfiltrating data over SMTP port 587 using STARTTLS. The attack uses reflective code loading and process injection to evade detection and minimize disk artifacts. This campaign targets victims primarily in Malaysia and leverages trusted business workflows to increase success rates.

Potential Impact

The Phantom Stealer malware harvests credentials from web browsers, cryptocurrency wallets, messaging applications, and collects system information. Stolen data is exfiltrated securely via SMTP with STARTTLS encryption, potentially leading to credential compromise, financial theft, and unauthorized access to victim systems. The multi-stage, in-memory execution and process injection techniques reduce detection likelihood by traditional security solutions, increasing the risk of prolonged undetected compromise.

Mitigation Recommendations

No official patch or remediation is available as this is a malware campaign rather than a software vulnerability. Defenders should focus on user awareness to recognize phishing attempts impersonating trusted business entities. Endpoint detection solutions should be tuned to detect behaviors such as in-memory PowerShell execution, reflective code loading, process injection, and suspicious SMTP traffic on port 587. Network monitoring for anomalous SMTP exfiltration and blocking or quarantining suspicious compressed email attachments can help reduce risk. Since the malware operates primarily in memory and uses obfuscation, behavior-based detection is critical.

Affected Countries

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.seqrite.com/blog/abusing-trusted-business-workflows-a-multi-stage-phantom-stealer-campaign/"]
Adversary
null
Pulse Id
6a60df1ccbee3728dd9c71e5
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hash34bfa888695b9aaa41bd575245972043
hash5f238710a5ef4f6ddbbe7a118c822705
hash6bbfc88534d5d515dddb0ec9bb618530
hash8a620e451e64f418bc21fd458e952f2e
hasha30b628d0c087f305b35be3e3f5281b3
hashddb91e512fa3ae6a38eed741868526ffbc40a864
hash64a68e4e1b93f1347c0935875395672784db5b49027c6508f13983efa98971f8

Threat ID: 6a613f179c2644c7f8c4d928

Added to database: 07/22/2026, 22:07:19 UTC

Last enriched: 07/22/2026, 22:26:17 UTC

Last updated: 07/23/2026, 00:32:32 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses