Abusing Trusted Business Workflows: A Multi-Stage Phantom Stealer Campaign
This threat describes a sophisticated phishing campaign distributing Phantom Stealer v3.5.0 by impersonating trusted business entities such as UPS and the Malaysian Inland Revenue Board. The attack uses compressed archives containing malicious JavaScript that triggers obfuscated PowerShell scripts running entirely in memory. These scripts deploy multiple encrypted and encoded payload stages using Base64, AES, and XOR to evade detection. The final payload steals credentials from browsers, cryptocurrency wallets, messaging apps, and system information, exfiltrating data via SMTP with STARTTLS encryption. The campaign employs reflective code loading and process injection into legitimate binaries to reduce on-disk footprint and evade traditional defenses. The campaign is targeted notably at Malaysia. No known exploits in the wild or patches are indicated.
AI Analysis
Technical Summary
A multi-stage phishing campaign impersonates legitimate business entities to deliver Phantom Stealer v3.5.0. Initial infection vectors are emails with compressed archives containing malicious JavaScript files. Execution of these files launches obfuscated PowerShell scripts that operate solely in memory, deploying encrypted and encoded payloads through Base64 encoding, AES encryption, and XOR ciphering. The final payload harvests sensitive credentials and system information before exfiltrating data over SMTP port 587 using STARTTLS. The attack uses reflective code loading and process injection to evade detection and minimize disk artifacts. This campaign targets victims primarily in Malaysia and leverages trusted business workflows to increase success rates.
Potential Impact
The Phantom Stealer malware harvests credentials from web browsers, cryptocurrency wallets, messaging applications, and collects system information. Stolen data is exfiltrated securely via SMTP with STARTTLS encryption, potentially leading to credential compromise, financial theft, and unauthorized access to victim systems. The multi-stage, in-memory execution and process injection techniques reduce detection likelihood by traditional security solutions, increasing the risk of prolonged undetected compromise.
Mitigation Recommendations
No official patch or remediation is available as this is a malware campaign rather than a software vulnerability. Defenders should focus on user awareness to recognize phishing attempts impersonating trusted business entities. Endpoint detection solutions should be tuned to detect behaviors such as in-memory PowerShell execution, reflective code loading, process injection, and suspicious SMTP traffic on port 587. Network monitoring for anomalous SMTP exfiltration and blocking or quarantining suspicious compressed email attachments can help reduce risk. Since the malware operates primarily in memory and uses obfuscation, behavior-based detection is critical.
Affected Countries
Malaysia
Indicators of Compromise
- hash: 34bfa888695b9aaa41bd575245972043
- hash: 5f238710a5ef4f6ddbbe7a118c822705
- hash: 6bbfc88534d5d515dddb0ec9bb618530
- hash: 8a620e451e64f418bc21fd458e952f2e
- hash: a30b628d0c087f305b35be3e3f5281b3
- hash: ddb91e512fa3ae6a38eed741868526ffbc40a864
- hash: 64a68e4e1b93f1347c0935875395672784db5b49027c6508f13983efa98971f8
Abusing Trusted Business Workflows: A Multi-Stage Phantom Stealer Campaign
Description
This threat describes a sophisticated phishing campaign distributing Phantom Stealer v3.5.0 by impersonating trusted business entities such as UPS and the Malaysian Inland Revenue Board. The attack uses compressed archives containing malicious JavaScript that triggers obfuscated PowerShell scripts running entirely in memory. These scripts deploy multiple encrypted and encoded payload stages using Base64, AES, and XOR to evade detection. The final payload steals credentials from browsers, cryptocurrency wallets, messaging apps, and system information, exfiltrating data via SMTP with STARTTLS encryption. The campaign employs reflective code loading and process injection into legitimate binaries to reduce on-disk footprint and evade traditional defenses. The campaign is targeted notably at Malaysia. No known exploits in the wild or patches are indicated.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
A multi-stage phishing campaign impersonates legitimate business entities to deliver Phantom Stealer v3.5.0. Initial infection vectors are emails with compressed archives containing malicious JavaScript files. Execution of these files launches obfuscated PowerShell scripts that operate solely in memory, deploying encrypted and encoded payloads through Base64 encoding, AES encryption, and XOR ciphering. The final payload harvests sensitive credentials and system information before exfiltrating data over SMTP port 587 using STARTTLS. The attack uses reflective code loading and process injection to evade detection and minimize disk artifacts. This campaign targets victims primarily in Malaysia and leverages trusted business workflows to increase success rates.
Potential Impact
The Phantom Stealer malware harvests credentials from web browsers, cryptocurrency wallets, messaging applications, and collects system information. Stolen data is exfiltrated securely via SMTP with STARTTLS encryption, potentially leading to credential compromise, financial theft, and unauthorized access to victim systems. The multi-stage, in-memory execution and process injection techniques reduce detection likelihood by traditional security solutions, increasing the risk of prolonged undetected compromise.
Mitigation Recommendations
No official patch or remediation is available as this is a malware campaign rather than a software vulnerability. Defenders should focus on user awareness to recognize phishing attempts impersonating trusted business entities. Endpoint detection solutions should be tuned to detect behaviors such as in-memory PowerShell execution, reflective code loading, process injection, and suspicious SMTP traffic on port 587. Network monitoring for anomalous SMTP exfiltration and blocking or quarantining suspicious compressed email attachments can help reduce risk. Since the malware operates primarily in memory and uses obfuscation, behavior-based detection is critical.
Affected Countries
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.seqrite.com/blog/abusing-trusted-business-workflows-a-multi-stage-phantom-stealer-campaign/"]
- Adversary
- null
- Pulse Id
- 6a60df1ccbee3728dd9c71e5
- Threat Score
- null
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hash34bfa888695b9aaa41bd575245972043 | — | |
hash5f238710a5ef4f6ddbbe7a118c822705 | — | |
hash6bbfc88534d5d515dddb0ec9bb618530 | — | |
hash8a620e451e64f418bc21fd458e952f2e | — | |
hasha30b628d0c087f305b35be3e3f5281b3 | — | |
hashddb91e512fa3ae6a38eed741868526ffbc40a864 | — | |
hash64a68e4e1b93f1347c0935875395672784db5b49027c6508f13983efa98971f8 | — |
Threat ID: 6a613f179c2644c7f8c4d928
Added to database: 07/22/2026, 22:07:19 UTC
Last enriched: 07/22/2026, 22:26:17 UTC
Last updated: 07/23/2026, 00:32:32 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.