Phantom Stealer Hides Inside PNG Files, Then Steals Your Passwords, Cookies and Crypto
Brief
Phantom Stealer is taking a familiar computer file and turning it into a hiding place.
The credential-stealing malware can conceal its next stage in PNG resources, then quietly collect passwords, browser cookies, cryptocurrency wallet material and other valuable data from Windows systems.
The threat has appeared in campaigns aimed at users in several countries.
Its operators use phishing emails, pirated software and malicious links circulated through Discord and Telegram, making an infection possible wherever a tempting download or message gets a click.
Analysts at Splunk identified the malware as a .NET-based stealer with a modular design that can help both less experienced and established criminals deploy it.
