SYMBOLCOMMON_NAMEaka. SYNONYMS
win.phantom_stealer (Back to overview)

Phantom Stealer


According to Proofpoint, this is a fork of Stealerium that has high overlap with its originating codebase.

References
2025-09-03ProofpointKyle Cucci, Proofpoint Threat Research Team, Rob Kinner
Not Safe for Work: Tracking and Investigating Stealerium and Phantom Infostealers
Phantom Stealer

There is no Yara-Signature yet.