216.73.216.6

Operation MoneyMount, ISO Deploying Phantom Stealer

· Published 12/12/2025 08:45 · Modified 21/12/2025 19:01

Export JSON

Essential information

Published
12/12/2025 08:45
Modified
21/12/2025 19:01
Tags
2025-12-12 credential-theft exfiltration finance iso multi-stage attack phantom stealer phishing russia steganography
Related entities
4 observables, 1 malware, 2 others

Description

A Russian campaign targeting and accounting sectors uses fake payment confirmation emails to deliver malware. The attack chain involves a ZIP file containing an , which when mounted reveals an executable that loads the stealer. The malware employs anti-analysis techniques, extracts crypto wallets, browser data, and Discord tokens. It also includes keylogging and clipboard monitoring capabilities. The stolen data is exfiltrated via Telegram, Discord webhooks, or FTP. The operation showcases the increasing sophistication of commodity stealers and the strategic use of files for initial access to evade security controls.

External references