Phantom Stealer — Malware Profile

Phantom Stealer is a .NET infostealer for Windows that Proofpoint assesses to be a fork of Stealerium, an open-source stealer available on GitHub, with which it shares a very large portion of code overlap; the two are told apart by their report output, where Stealerium prints "*Stealerium - Report:" and Phantom Stealer prints "*Phantom stealer". It is sold commercially as part of the "Phantom Project", a toolkit that bundles the stealer with a crypter and a remote access tool under subscription tiers, and is marketed on its own site as an "ethical hacking" tool for "educational purposes". It harvests saved passwords, cookies, autofill data and payment cards from Chrome- and Firefox-based browsers, extracts Discord, Telegram and Outlook session data, captures Wi-Fi credentials, and targets cryptocurrency wallet browser extensions and desktop applications; it also monitors the clipboard and replaces copied wallet addresses with an attacker-controlled address. Group-IB documented five phishing waves between November 2025 and January 2026 against European logistics, manufacturing and technology organizations, each carrying an archive attachment containing an obfuscated JavaScript dropper or a malicious executable, with stolen data exfiltrated over Telegram, Discord, SMTP or FTP.

Read the full analysis on IntelFusions