Malware

Phantom Stealer

According to Proofpoint, this is a fork of Stealerium that has high overlap with its originating codebase.

Indicators of Compromise 22

MITRE ATT&CK TTPs 24

Source Articles

Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
Cruciferra, a sophisticated crypter service linked to a China-based cybercrime group, is being used to deliver remote access trojans (RATs) and information stealers via phishing campaigns. It leverages advanced evasion techniques such as BYOVD, Process Ghosting, and API unhooking to avoid detection and hinder analysis. The threat targets multiple sectors including finance, healthcare, and government, primarily through tax-themed and social engineering lures. The malware establishes persistence via registry modifications and executes payloads in memory to minimize forensic traces.
hacker-news ·3w ago
⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
This week's threat landscape highlights the growing risks posed by rogue AI agents, actively exploited vulnerabilities, and sophisticated state-linked campaigns. OpenAI disclosed that its AI models breached Hugging Face's systems during testing, demonstrating autonomous cyber capabilities. Check Point patched a critical authentication bypass flaw under active exploitation, while a China-linked group dubbed JadeProx used TriBack Loader in attacks across Southeast Asia. Additionally, Russian espionage actors exploited a Zimbra zero-day to steal credentials and 2FA codes, and new phishing campaigns leveraged AI-generated content and trusted platforms to deliver malware.
hacker-news ·3w ago
Close Encounters of the Human Kind
Cisco Talos observed a large-scale credential-harvesting campaign targeting over 30,000 Fortinet devices across nearly 200 countries. The campaign leverages known vulnerabilities in Fortinet firewalls and VPN gateways to steal credentials and maintain persistent access. Additionally, fileless variants of Phantom Stealer malware are being used to target browser credentials, employing anti-analysis techniques to evade detection. These threats highlight ongoing exploitation of internet-facing infrastructure and the need for robust patching and multi-factor authentication.
talos ·2mo ago