Abusing Trusted Business Workflows: A Multi-Stage Phantom Stealer Campaign
A sophisticated phishing campaign impersonates legitimate business entities including UPS and the Malaysian Inland Revenue Board to distribute Phantom Stealer v3.5.0. The attack begins with convincing emails containing compressed archives housing malicious JavaScript files. Once executed, the JavaScript launches obfuscated PowerShell scripts that operate entirely in memory, deploying multiple stages of encrypted and encoded payloads. The infection chain utilizes Base64 encoding, AES encryption, and XOR ciphering to conceal its activities. The final payload, Phantom Stealer, harvests credentials from browsers, cryptocurrency wallets, messaging applications, and system information before exfiltrating stolen data via SMTP over port 587 using STARTTLS encryption. The multi-layered approach significantly reduces on-disk footprint and employs reflective code loading and process injection into legitimate binaries to evade traditional security defenses.
AI Analysis
Technical Summary
A multi-stage phishing campaign impersonates legitimate business entities to deliver Phantom Stealer v3.5.0. Initial infection vectors are emails with compressed archives containing malicious JavaScript files. Execution of these files launches obfuscated PowerShell scripts that operate solely in memory, deploying encrypted and encoded payloads through Base64 encoding, AES encryption, and XOR ciphering. The final payload harvests sensitive credentials and system information before exfiltrating data over SMTP port 587 using STARTTLS. The attack uses reflective code loading and process injection to evade detection and minimize disk artifacts. This campaign targets victims primarily in Malaysia and leverages trusted business workflows to increase success rates.
Potential Impact
The Phantom Stealer malware harvests credentials from web browsers, cryptocurrency wallets, messaging applications, and collects system information. Stolen data is exfiltrated securely via SMTP with STARTTLS encryption, potentially leading to credential compromise, financial theft, and unauthorized access to victim systems. The multi-stage, in-memory execution and process injection techniques reduce detection likelihood by traditional security solutions, increasing the risk of prolonged undetected compromise.
Mitigation Recommendations
No official patch or remediation is available as this is a malware campaign rather than a software vulnerability. Defenders should focus on user awareness to recognize phishing attempts impersonating trusted business entities. Endpoint detection solutions should be tuned to detect behaviors such as in-memory PowerShell execution, reflective code loading, process injection, and suspicious SMTP traffic on port 587. Network monitoring for anomalous SMTP exfiltration and blocking or quarantining suspicious compressed email attachments can help reduce risk. Since the malware operates primarily in memory and uses obfuscation, behavior-based detection is critical.
Affected Countries
Malaysia
Indicators of Compromise
- hash: 34bfa888695b9aaa41bd575245972043
- hash: 5f238710a5ef4f6ddbbe7a118c822705
- hash: 6bbfc88534d5d515dddb0ec9bb618530
- hash: 8a620e451e64f418bc21fd458e952f2e
- hash: a30b628d0c087f305b35be3e3f5281b3
- hash: ddb91e512fa3ae6a38eed741868526ffbc40a864
- hash: 64a68e4e1b93f1347c0935875395672784db5b49027c6508f13983efa98971f8
Abusing Trusted Business Workflows: A Multi-Stage Phantom Stealer Campaign
Description
A sophisticated phishing campaign impersonates legitimate business entities including UPS and the Malaysian Inland Revenue Board to distribute Phantom Stealer v3.5.0. The attack begins with convincing emails containing compressed archives housing malicious JavaScript files. Once executed, the JavaScript launches obfuscated PowerShell scripts that operate entirely in memory, deploying multiple stages of encrypted and encoded payloads. The infection chain utilizes Base64 encoding, AES encryption, and XOR ciphering to conceal its activities. The final payload, Phantom Stealer, harvests credentials from browsers, cryptocurrency wallets, messaging applications, and system information before exfiltrating stolen data via SMTP over port 587 using STARTTLS encryption. The multi-layered approach significantly reduces on-disk footprint and employs reflective code loading and process injection into legitimate binaries to evade traditional security defenses.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
A multi-stage phishing campaign impersonates legitimate business entities to deliver Phantom Stealer v3.5.0. Initial infection vectors are emails with compressed archives containing malicious JavaScript files. Execution of these files launches obfuscated PowerShell scripts that operate solely in memory, deploying encrypted and encoded payloads through Base64 encoding, AES encryption, and XOR ciphering. The final payload harvests sensitive credentials and system information before exfiltrating data over SMTP port 587 using STARTTLS. The attack uses reflective code loading and process injection to evade detection and minimize disk artifacts. This campaign targets victims primarily in Malaysia and leverages trusted business workflows to increase success rates.
Potential Impact
The Phantom Stealer malware harvests credentials from web browsers, cryptocurrency wallets, messaging applications, and collects system information. Stolen data is exfiltrated securely via SMTP with STARTTLS encryption, potentially leading to credential compromise, financial theft, and unauthorized access to victim systems. The multi-stage, in-memory execution and process injection techniques reduce detection likelihood by traditional security solutions, increasing the risk of prolonged undetected compromise.
Defensive Guidance
No official patch or remediation is available as this is a malware campaign rather than a software vulnerability. Defenders should focus on user awareness to recognize phishing attempts impersonating trusted business entities. Endpoint detection solutions should be tuned to detect behaviors such as in-memory PowerShell execution, reflective code loading, process injection, and suspicious SMTP traffic on port 587. Network monitoring for anomalous SMTP exfiltration and blocking or quarantining suspicious compressed email attachments can help reduce risk. Since the malware operates primarily in memory and uses obfuscation, behavior-based detection is critical.
Affected Countries
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.seqrite.com/blog/abusing-trusted-business-workflows-a-multi-stage-phantom-stealer-campaign/"]
- Adversary
- null
- Pulse Id
- 6a60df1ccbee3728dd9c71e5
- Threat Score
- null
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hash34bfa888695b9aaa41bd575245972043 | — | |
hash5f238710a5ef4f6ddbbe7a118c822705 | — | |
hash6bbfc88534d5d515dddb0ec9bb618530 | — | |
hash8a620e451e64f418bc21fd458e952f2e | — | |
hasha30b628d0c087f305b35be3e3f5281b3 | — | |
hashddb91e512fa3ae6a38eed741868526ffbc40a864 | — | |
hash64a68e4e1b93f1347c0935875395672784db5b49027c6508f13983efa98971f8 | — |
Threat ID: 6a613f179c2644c7f8c4d928
Added to database: 07/22/2026, 22:07:19 UTC
Last enriched: 07/22/2026, 22:26:17 UTC
Last updated: 09/04/2026, 23:26:33 UTC
Views: 174
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.