Phantom Stealer transforms familiar files into hidden locations. The credential-stealing malware conceals its next phase within PNG resources, gathering passwords, browser cookies, cryptocurrency wallet details, and other valuable data from Windows systems. Attackers use phishing emails, pirated software, malicious links on Discord and Telegram to initiate infections wherever enticing downloads or messages receive clicks.
That flexibility increases risks: stolen session cookies allow unauthorized access without knowing the password, while wallet data can lead to financial losses directly. Phantom Stealer Conceals Inside PNG Files The PNG file is not necessarily the initial entry point for infection; in one observed scenario, a .NET loader stores an executable within a PNG entry as part of its own resources.
Researchers observed it targeting specific documents, databases, FileZilla settings, WinSCP credentials, Outlook profile information, screenshots, typed keystrokes, and saved Wi-Fi profiles. Defenders must investigate unusual PowerShell activity, remote process injection, non-browser programs accessing browser data, and browsers launched with a custom user-data directory or no-sandbox setting. Indicators of Compromise (IoCs): Type Indicator Description SHA-256 b588caa5365451a6c60fd73fec5b73f13ac41bcc2a3a3bed7244df5917a62f32 Phantom Stealer Loader; Phantom Stealer PowerShell Loader SHA-256 382233c398cbc35dcee845ee17046815f37588a382a8106bfb9b0252ea803961 Phantom Stealer Batch Loader SHA-256 790945e17a51691483455a11af2efcbe15f2b473b65b151f50287623d1468516 Phantom Stealer SHA-256 01f1e5369aa0332abb681df7c37818e197ec0a5b5d7b81836b3369a2b1780950 Phantom Stealer SHA-256 10cfcad907275497dab92af0d687674cec3a0333f80dd16d8d22254794bb2d60 Phantom Stealer SHA-256 2d5003d9318ae85eb22de99d19705a3cd7bf8e5c3349df979dfb3bdfa080908e Phantom Stealer SHA-256 528a46842744366b57edfc6fe2810ca7df43900db75126cd1c78f32957143364 Phantom Stealer SHA-256 e3ceeb24bdca8842d426e87fa61cf185d68fd7783e1a2b97d4106832ca266724 Phantom Stealer SHA-256 f82a4d30132b5a57cbfd81c7ab0a53d0cf0dda402c2731732a0097aceb4b0b76 Phantom Stealer SHA-256 be119a21bedc3a79bf4dea8bcf5adf18304997a01ea23e276b9c31be37b789ab Phantom Stealer JavaScript Loader












