Phishing, Cracked Software and Discord Links Spread Phantom Stealer Across Multiple Countries
Brief
Phantom Stealer, a .NET-based information-stealing malware, is being distributed through phishing emails, pirated software downloads, and malicious links shared on Discord and Telegram.
The malware is designed to silently collect browser credentials, saved passwords, cookies, cryptocurrency wallet data, system details, and other sensitive information from infected Windows devices.
Security researchers have observed Phantom Stealer in campaigns targeting victims across several countries.
Its modular structure, flexible delivery methods, and strong focus on credential theft make it a growing concern for both individuals and organizations.
The malware is commonly delivered through phishing lures, trojanized applications , and malicious downloads that persuade users to launch an archive, script, or fake installer.
