HomeSecurityPhantom Stealer: Phishing attack with ISO images targets Russia

Phantom Stealer: Phishing attack with ISO images targets Russia

Cybersecurity researchers have revealed details of an active phishing campaign targeting various domains in Russia with phishing emails delivering Phantom Stealer (via malicious ISO optical disc images).

Phantom Stealer

The operation is being tracked as Operation MoneyMount-ISO by Seqrite Labs and primarily targets financial and accounting entities.

“ This campaign uses a fake payment confirmation to deliver the information-stealing through a multi-layered chain of attachments Phantom malware ,” the cybersecurity firm said

See also: VolkLocker ransomware allows free decryption

Phantom Stealer: How the phishing attack works

The infection chain begins with a phishing email that pretends to be a legitimate financial communication, inviting recipients to confirm a recent bank transfer. Attached to the email is a ZIP that claims to contain additional details, but actually contains an ISO file that, when launched, mounts on the system as a virtual CD drive.

The ISO image (“Подтверждение банковского перевода.iso” or “Confirmation of bank transfer.iso”) functions as an executable file designed to launch Phantom Stealer via an embedded DLL (“CreativeAI.dll”).

See also: Abuse of Paypal for phishing attacks

Malware characteristics

Phantom Stealer can extract data from cryptocurrency wallet extensions (installed on Chromium-based browsers) as well as desktop wallet apps . It also grabs files, Discord authentication tokens and passwords, cookies , and credit card details associated with browsers. It monitors clipboard content , logs keystrokes , and performs checks to detect virtual, sandboxed, or analysis environments, stopping execution if necessary.

Phantom Stealer: Phishing attack with ISO images targets Russia

Data extraction is achieved through a Telegram bot or a Discord webhook controlled by the attacker and allowing files to be transferred to an FTP server.

Other campaigns

In recent months, Russian organizations, particularly HR and payroll departments, have also been targeted by phishing emails that use bait about bonuses or internal financial policies. The aim is to develop a new implant called DUPERUNNER that loads AdaptixC2, an open-source command-and-control (C2) framework.

See also: New AiTM attack campaign targets Microsoft 365 and Okta users

Other phishing campaigns have targeted the financial, legal, and aerospace sectors in Russia to distribute Cobalt Strike and malicious tools such as Formbook, DarkWatchman, and PhantomRemote, capable of data theft and keystroke spoofing. The email servers of compromised Russian companies are used to send the spear-phishing messages.

Phantom Stealer: Phishing attack with ISO images targets Russia

French cybersecurity firm Intrinsec has attributed the attacks on the Russian aerospace industry to hacktivists aligned with Ukrainian interests. The activity, detected between June and September 2025, shares overlaps with Hive0117, Operation CargoTalon, and Rainbow Hyena (also known as Fairy Trickster, Head Mare, and PhantomCore).

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS