cognitive cybersecurity intelligence

News and Analysis

Search

Phantom Stealer Hides Inside PNG Files, Then Steals Your Passwords, Cookies and Crypto

Phantom Stealer Hides Inside PNG Files, Then Steals Your Passwords, Cookies and Crypto

Phantom Stealer is taking a familiar computer file and turning it into a hiding place.

The credential-stealing malware can conceal its next stage in PNG resources, then quietly collect passwords, browser cookies, cryptocurrency wallet material and other valuable data from Windows systems.

The threat has appeared in campaigns aimed at users in several countries.

Its operators use phishing emails, pirated software and malicious links circulated through Discord and Telegram, making an infection possible wherever a tempting download or message gets a click.

Analysts at Splunk identified the malware as a .NET-based stealer with a modular design that can help both less experienced and established criminals deploy it.

That flexibility raises the stakes: stolen session cookies can let an intruder enter an account without knowing the password, while wallet data can lead directly to financial loss.

Splunk said in a report shared with Cyber Security News (CSN) that the malware can stay hidden, keep access after a restart, and gather browser, wallet, file and clipboard data.

Its use of image-borne payloads also echoes recent PNG steganography campaigns, where normal-looking graphics carry code that scanners may overlook.

Phantom Stealer Hides Inside PNG Files

The PNG file is not necessarily the item that starts the infection. In one observed chain, a .NET loader stores an executable in a PNG entry within its own resources.

The concealed data is encrypted, and the loader decrypts it to reveal Phantom Stealer only after it has started, frustrating quick file inspection.

That approach is called steganography, meaning information is hidden inside an ordinary-looking file.

It is particularly useful because image files are common and often trusted. Readers may recall earlier image hiding attacks, which similarly used encrypted material disguised as PNG content.

Another loader arrived through a phishing email as a heavily obscured PowerShell script.

It decrypted code and placed it inside explorer.exe, a normal Windows process. From there, it can unpack the final stealer and weaken visibility by interfering with Windows security scanning and event logging.

Phantom Stealer Steganography Loader Extraction (Source – Splunk)

The supplied research illustrates extraction of the next-stage content hidden in two image files.

The practical lesson is simple: a picture file alone is not proof of danger, but unexpected image resources paired with script activity deserve close review.

Passwords, Cookies And Crypto At Risk

Once active, Phantom Stealer searches browser databases and configuration files for saved usernames, passwords, profiles, cookies and payment-card data.

Cookies matter because they can preserve an authenticated web session. This makes browser session theft risks a concern even for people who use multi-factor authentication.

The malware also copies data from cryptocurrency wallet browser extensions and desktop wallet applications. It watches the clipboard, looking for wallet addresses.

Extracted Phantom Stealer Payload (Source – Splunk)

When it finds one, it can replace the copied address with an attacker-controlled value, potentially sending a payment to the wrong recipient when the victim pastes it.

Its reach extends beyond browsers. Researchers observed it seeking selected documents and databases, FileZilla settings, saved WinSCP credentials, Outlook profile information, screenshots, typed keystrokes and saved Wi-Fi profiles.

It can create a Registry Run entry or use the Startup folder so it launches again after reboot.

Before stealing data, it checks system, account, processes, services and network details for signs it is inside a sandbox. It can slow or halt when it suspects analysis.

This means a test result should not be treated as final, especially when a sample has not completed timing checks. It starts Chrome with command line settings to isolate work from the victim’s browser session.

Defenders should investigate unusual PowerShell activity, remote process injection, non-browser programs accessing browser data, and browsers launched with a custom user-data directory or no-sandbox setting.

Security teams should also inspect suspicious downloads and email attachments, block unauthorized software, and rotate passwords, sessions and wallet credentials after a confirmed infection.

Similar crypto wallet targeting tactics show why affected assets should be treated as exposed immediately.

Indicators of compromise (IoCs):-

TypeIndicatorDescriptionSHA-256b588caa5365451a6c60fd73fec5b73f13ac41bcc2a3a3bed7244df5917a62f32Phantom Stealer Loader; Phantom Stealer PowerShell LoaderSHA-256382233c398cbc35dcee845ee17046815f37588a382a8106bfb9b0252ea803961Phantom Stealer Batch LoaderSHA-256790945e17a51691483455a11af2efcbe15f2b473b65b151f50287623d1468516Phantom StealerSHA-25601f1e5369aa0332abb681df7c37818e197ec0a5b5d7b81836b3369a2b1780950Phantom StealerSHA-25610cfcad907275497dab92af0d687674cec3a0333f80dd16d8d22254794bb2d60Phantom StealerSHA-2562d5003d9318ae85eb22de99d19705a3cd7bf8e5c3349df979dfb3bdfa080908ePhantom StealerSHA-256528a46842744366b57edfc6fe2810ca7df43900db75126cd1c78f32957143364Phantom StealerSHA-256e3ceeb24bdca8842d426e87fa61cf185d68fd7783e1a2b97d4106832ca266724Phantom StealerSHA-256f82a4d30132b5a57cbfd81c7ab0a53d0cf0dda402c2731732a0097aceb4b0b76Phantom StealerSHA-256be119a21bedc3a79bf4dea8bcf5adf18304997a01ea23e276b9c31be37b789abPhantom Stealer JavaScript Loader

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world
The post Phantom Stealer Hides Inside PNG Files, Then Steals Your Passwords, Cookies and Crypto appeared first on Cyber Security News.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts