Threats Tagged 'injector'
View all threats tagged with 'injector'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'injector'
Click on any threat for detailed analysis and mitigation recommendations
Beware of Phishing Emails Disguised as Quote Confirmation Requests (PhantomStealer) 0 A phishing campaign has been identified where attackers impersonate sales staff from specific overseas companies, requesting quotation modifications and product version confirmations. The email contains a malicious GZ compressed file that, when extracted, delivers an injector-type executable. This injector employs multiple UAC bypass techniques including SSPI-based authentication and CMSTPLUA COM exploitation to gain elevated privileges. It then performs BYOVD attacks using the vulnerable DCRCVDrv.sys driver to terminate security products through kernel-level access. Following security product neutralization, the injector uses process hollowing to inject PhantomStealer into the legitimate AddInProcess32.exe process. PhantomStealer then executes comprehensive information theft including keylogging, screen capture, browser credentials, cryptocurrency wallet data, and clipboard manipulation to replace wallet addresses with attacker-controlled ones. Join the discussion | AlienVault OTX General | 08/19/2026, 07:28:55 UTC Added: 08/19/2026, 10:04:41 UTC |
Showing 1 to 1 of 1 result