Threats Tagged 'reflective loading'
View all threats tagged with 'reflective loading'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'reflective loading'
Click on any threat for detailed analysis and mitigation recommendations
Abusing Trusted Business Workflows: A Multi-Stage Phantom Stealer Campaign 0 This threat describes a sophisticated phishing campaign distributing Phantom Stealer v3.5.0 by impersonating trusted business entities such as UPS and the Malaysian Inland Revenue Board. The attack uses compressed archives containing malicious JavaScript that triggers obfuscated PowerShell scripts running entirely in memory. These scripts deploy multiple encrypted and encoded payload stages using Base64, AES, and XOR to evade detection. The final payload steals credentials from browsers, cryptocurrency wallets, messaging apps, and system information, exfiltrating data via SMTP with STARTTLS encryption. The campaign employs reflective code loading and process injection into legitimate binaries to reduce on-disk footprint and evade traditional defenses. The campaign is targeted notably at Malaysia. No known exploits in the wild or patches are indicated. Join the discussion | AlienVault OTX General | 07/22/2026, 15:17:48 UTC Added: 07/22/2026, 22:07:19 UTC |
Showing 1 to 1 of 1 result