Phantom Stealer
- First seen
- 2022-11-01 00:00:00
- Malware type
- credential-stealer, keylogger, spyware
- Family
- Malware family
- Last IoC activity
- 2026-07-22 02:45:34
- Profile updated
- 2026-07-07 15:15:35
Targeted industries: financial-services technology-and-telecommunications
Context
According to Proofpoint, this is a fork of Stealerium that has high overlap with its originating codebase.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Phantom Stealer (report)
- proofpoint.com — Not Safe Work Tracking And Investigating Stealerium And Phantom Infostealers (report)