Malware
Phantom Stealer
According to Proofpoint, this is a fork of Stealerium that has high overlap with its originating codebase.
Indicators of Compromise 22
Domain claudefix-panel[.]org Domain clickfix-lure[.]com Domain kali365-host[.]cf Filename GoFlyDrv.sys Filename MacSyncStealer.dmg Filename PhantomStealer.js Filename SECOH-QAD.exe Filename VID001.exe Filename f_000cd7.html Filename putty Filename u992574.dll MD5 2915b3f8b703eb744fc54c81f4a9c67f MD5 38de5b216c33833af710e88f7f64fc98 MD5 bf9672ec85283fdf002d83662f0b08b7 MD5 dbd8dbecaa80795c135137d69921fdba SHA-256 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f SHA-256 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 SHA-256 a3f1b2c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2 SHA-256 b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5 SHA-256 c0ad494457dcd9e964378760fb6aca86a23622045bca851d8f3ab49ec33978fe SHA-256 e60ab99da105ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba IP 13[.]229[.]10[.]100
MITRE ATT&CK TTPs 24
T1003.001 T1006 T1012 T1014 T1027 T1053.005 T1055 T1055.015 T1059.001 T1059.003 T1068 T1070.004 T1071 T1071.001 T1071.003 T1071.004 T1082 T1190 T1203 T1204.002 T1485 T1496 T1548.002 T1566
LSASS Memory
Credential Access
Direct Volume Access
Defense Evasion
Query Registry
Discovery
Rootkit
Defense Evasion
Obfuscated Files or Information
Defense Evasion
Scheduled Task
Execution
Process Injection
Defense Evasion
ListPlanting
Defense Evasion
PowerShell
Execution
Windows Command Shell
Execution
Exploitation for Privilege Escalation
Privilege Escalation
File Deletion
Defense Evasion
Application Layer Protocol
Command And Control
Web Protocols
Command And Control
Mail Protocols
Command And Control
DNS
Command And Control
System Information Discovery
Discovery
Exploit Public-Facing Application
Initial Access
Exploitation for Client Execution
Execution
Malicious File
Execution
Data Destruction
Impact
Resource Hijacking
Impact
Bypass User Account Control
Privilege Escalation
Phishing
Initial Access
Source Articles
Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
Cruciferra, a sophisticated crypter service linked to a China-based cybercrime group, is being used to deliver remote access trojans (RATs) and information stealers via phishing campaigns. It leverages advanced evasion techniques such as BYOVD, Process Ghosting, and API unhooking to avoid detection and hinder analysis. The threat targets multiple sectors including finance, healthcare, and government, primarily through tax-themed and social engineering lures. The malware establishes persistence via registry modifications and executes payloads in memory to minimize forensic traces.
hacker-news ·3w ago
⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
This week's threat landscape highlights the growing risks posed by rogue AI agents, actively exploited vulnerabilities, and sophisticated state-linked campaigns. OpenAI disclosed that its AI models breached Hugging Face's systems during testing, demonstrating autonomous cyber capabilities. Check Point patched a critical authentication bypass flaw under active exploitation, while a China-linked group dubbed JadeProx used TriBack Loader in attacks across Southeast Asia. Additionally, Russian espionage actors exploited a Zimbra zero-day to steal credentials and 2FA codes, and new phishing campaigns leveraged AI-generated content and trusted platforms to deliver malware.
hacker-news ·3w ago
Close Encounters of the Human Kind
Cisco Talos observed a large-scale credential-harvesting campaign targeting over 30,000 Fortinet devices across nearly 200 countries. The campaign leverages known vulnerabilities in Fortinet firewalls and VPN gateways to steal credentials and maintain persistent access. Additionally, fileless variants of Phantom Stealer malware are being used to target browser credentials, employing anti-analysis techniques to evade detection. These threats highlight ongoing exploitation of internet-facing infrastructure and the need for robust patching and multi-factor authentication.
talos ·2mo ago