Operation MoneyMount, ISO Deploying Phantom Stealer
Essential information
- Published
- 12/12/2025 08:45
- Modified
- 21/12/2025 19:01
- Tags
- 2025-12-12 credential-theft exfiltration finance iso multi-stage attack phantom stealer phishing russia steganography
- Related entities
- 4 observables, 1 malware, 2 others
Description
A Russian phishing campaign targeting finance and accounting sectors uses fake payment confirmation emails to deliver Phantom stealer malware. The attack chain involves a ZIP file containing an ISO, which when mounted reveals an executable that loads the stealer. The malware employs anti-analysis techniques, extracts crypto wallets, browser data, and Discord tokens. It also includes keylogging and clipboard monitoring capabilities. The stolen data is exfiltrated via Telegram, Discord webhooks, or FTP. The operation showcases the increasing sophistication of commodity stealers and the strategic use of ISO files for initial access to evade security controls.