HomeCyber BalkansPhantom Stealer Campaign Employs JavaScript and PowerShell to Theft Browser Credentials

Phantom Stealer Campaign Employs JavaScript and PowerShell to Theft Browser Credentials

Published on

spot_img

Phishing Campaign Unveils Advanced Malware Delivery System

A sophisticated phishing campaign has emerged that expertly disguises malware delivery within routine business communications, ultimately deploying Phantom Stealer v3.5.0. This advanced malware is designed to harvest sensitive information, including browser credentials, cookies, payment data, and cryptocurrency wallet information from unsuspecting victims. Documented by cybersecurity firm Seqrite, the campaign effectively utilizes social engineering tactics that appeal to business-related contexts, enhancing its potential for success.

Dual Phishing Themes

The campaign is characterized by two distinct phishing themes, both leading to the same infection chain. One email masquerades as a notification from the UPS Forwarding Hub, referencing fictitious shipment bookings and quotation IDs designed to target procurement teams within organizations. This strategy capitalizes on the natural workflow of procurement personnel, preying on their routine tasks and tempting them to engage with the email.

The second phishing theme appears as an official notice from Malaysia’s Inland Revenue Board (LHDN), written in Malay and demanding urgent tax documentation. By imposing a tight 14-day deadline, the attackers compel finance staff to act quickly, making it more likely that individuals will overlook potential warning signs of fraud.

Both phishing emails contain compressed archives that house a malicious JavaScript file, cleverly named with business-relevant titles such as “UPS Docs_Shipment Number 3264010420.js.” This naming convention is particularly insidious, as it is designed to blend seamlessly into normal workflows and evade the scrutiny that typically accompanies suspicious files.

The Infection Process

Once the infected JavaScript file is executed, it acts solely as a loader. This multi-layered design obscures its true purpose and functions to make detection through static analysis significantly more difficult. The infection process unfolds in several stages:

  1. Stage 1: The obfuscated JavaScript employs string-array obfuscation and indirect function calls to conceal its intent. It decodes an embedded Base64 blob containing a PowerShell script, which is then written to a temporary .ps1 file and executed using hidden powershell.exe parameters.

  2. Stage 2: The PowerShell script decrypts an AES-encrypted payload, utilizing keys and IVs that are embedded within the script as Base64 strings. This payload is executed directly in memory, thus avoiding any disk writes.

  3. Stage 3: A second PowerShell loader extracts two payloads: an XOR-encrypted .NET “injector” assembly and a raw byte-array PE file that corresponds with the Phantom Stealer executable. The injector utilizes reflective loading to inject the stealer into a legitimate process, specifically aspnet_compiler.exe.

  4. Stage 4: Phantom Stealer v3.5.0 runs completely in memory, collecting data before it can be exfiltrated.

This elaborate design reduces the malware’s footprint on disk, complicating its detection and removal.

Data Harvesting and Exfiltration

Phantom Stealer is adept at targeting a broad array of sensitive data. It categorizes stolen information into neatly organized files, which include Chromium-style passwords and cookies, Gecko passwords and cookies, as well as local data from cryptocurrency wallets and messaging applications on the compromised machine.

For data exfiltration, the malware establishes a connection with an SMTP server over port 587. It authenticates through Base64-encoded credentials, which were once verified to decode to a username linked to a specific domain. The connection is then upgraded with STARTTLS to encrypt the data transmission. This method allows the stolen data to blend in with legitimate outbound email traffic, wrapping up the session with a conventional QUIT command and leaving minimal traces of anomalous activity.

Interestingly, the analysis carried out by cybersecurity expert Prashil Moon revealed no definitive connections to a single threat actor. Rather, Phantom Stealer appears to be a form of commodity malware, utilized by various operators across the cybercriminal ecosystem.

Recommendations for Organizations

Given the rising frequency and sophistication of such attacks, organizations are urged to exercise caution when dealing with unexpected documents or attachments tied to shipments, banking, or tax-related matters. A solid defense strategy involves restricting unnecessary script execution where possible, and maintaining vigilant monitoring for unusual PowerShell activities, reflective memory loading, process injection, and atypical SMTP traffic.

Implementing a defense-in-depth approach—incorporating email security, endpoint monitoring, and network visibility—is critical in thwarting these multifaceted, fileless attacks prior to any sensitive data being compromised. The threat landscape is ever-evolving, and organizations must prepare to adapt their security measures accordingly.

Conclusion

In conclusion, the sophisticated phishing campaign leveraging Phantom Stealer v3.5.0 showcases the advanced techniques employed by cybercriminals to infiltrate organizations and exfiltrate valuable data. As organizations navigate the complex web of digital communications, staying educated and vigilant will be key in safeguarding assets against these evolving threats.

Source link

Latest articles

SBOM/CVE: The Shield in Cyber Warfare

We Are Conducting Security Drills for the Wrong Catastrophe: Understanding Cyber Threats Beyond "Duck...

AegisAI Secures $36M for AI-Driven Email Security

AegisAI Secures $36 Million in Series B Funding to Enhance Email Security AegisAI, a startup...

FBI and CISA Alert to Rising Iranian Cyber Attacks

Escalating Threats to Critical Infrastructure On July 22, 2026, federal agencies including the FBI, the...

Google Introduces Unified Cryptonym-Based Naming System for Threat Actors

In a significant development within the realm of cybersecurity, the Google Threat Intelligence Group...

More like this

SBOM/CVE: The Shield in Cyber Warfare

We Are Conducting Security Drills for the Wrong Catastrophe: Understanding Cyber Threats Beyond "Duck...

AegisAI Secures $36M for AI-Driven Email Security

AegisAI Secures $36 Million in Series B Funding to Enhance Email Security AegisAI, a startup...

FBI and CISA Alert to Rising Iranian Cyber Attacks

Escalating Threats to Critical Infrastructure On July 22, 2026, federal agencies including the FBI, the...