Russian Phishing Campaign Delivers Phantom Stealer Through Fake Bank Transfer Emails

Listen to this Post

Featured Image

🎯 Introduction: A Familiar Email With a Dangerous Twist

At first glance, the email looks routine. A formal subject line, professional Russian business language, and what appears to be a standard bank transfer confirmation. For finance teams, these messages arrive daily and rarely raise suspicion. But beneath this familiar surface, researchers have uncovered a carefully engineered phishing operation that turns trust into a weapon. A new campaign traced back to Russia is exploiting payment confirmation workflows to quietly deploy one of today’s more aggressive information-stealing threats: Phantom Stealer.

🧩 Summary of the Original Findings: How Operation MoneyMount-ISO Works

Seqrite Labs has identified an active and ongoing phishing campaign dubbed Operation MoneyMount-ISO, designed to infiltrate corporate financial environments and steal sensitive data. The operation primarily targets finance, accounting, and treasury departments within Russian-speaking organizations, while also extending its reach to procurement, HR, payroll, and legal teams that routinely process payment-related documentation.

The attackers rely heavily on social engineering rather than technical noise. Emails are written in polished, formal Russian, closely matching the tone and structure used in legitimate financial correspondence. The subject line, translated as “Confirmation of Bank Transfer,” is intentionally generic yet urgent, encouraging recipients to open the attachment without overthinking the request.

To increase credibility, the message impersonates TorFX Currency Broker, a real financial services brand. However, forensic analysis shows the email originates from spoofed addresses tied to unrelated Russian domains, a classic but effective deception tactic when paired with convincing content.

Attached to the email is a ZIP archive labeled as a bank transfer confirmation. Inside the archive is an ISO image file masquerading as a payment document. When opened, the ISO mounts automatically as a virtual drive, a behavior that many users associate with legitimate installation media rather than malicious content.

Within the mounted image sits an executable file disguised as a financial document. Once launched, it initiates the infection chain that ultimately deploys Phantom Stealer. This delivery method allows the malware to bypass numerous email security solutions that fail to deeply inspect ISO file systems.

Seqrite researchers observed that the attackers are financially motivated, focusing on credential harvesting, cryptocurrency wallet theft, and unauthorized access to enterprise financial workflows. Infrastructure patterns and domain usage suggest a coordinated threat cluster with a clear objective: monetize stolen access as quickly and quietly as possible.

🧠 Technical Breakdown: Inside the Phantom Stealer Infection Chain

At the technical level, the attack is both stealthy and resilient. When executed, the ISO-based payload loads an encrypted dynamic link library named CreativeAI.dll. This DLL decrypts the Phantom Stealer payload and injects it directly into system memory, avoiding disk-based detection mechanisms.

The malware is equipped with robust anti-analysis defenses. It actively checks for virtual machines, sandbox environments, and debugging tools. If monitoring activity is detected, Phantom Stealer can terminate itself, leaving minimal forensic traces behind.

Once active on a real system, the malware deploys multiple data extraction modules. It harvests saved credentials, browser cookies, and credit card information from Chromium-based browsers. It also targets Discord authentication tokens, a valuable asset for further social engineering or lateral movement.

Cryptocurrency users are hit especially hard. Phantom Stealer collects data from both browser-based and desktop crypto wallets, positioning attackers to directly drain digital assets. Additional surveillance features include clipboard monitoring and keystroke logging, with captured data stored in timestamped text files.

For exfiltration, the malware uses a mix of modern and unconventional channels. Stolen data is compressed into ZIP archives and sent via Telegram bot APIs, Discord webhooks, and traditional FTP servers. This diversity complicates detection and takedown efforts.

Seqrite tracks the malware as Trojan_Phantom_Y10018 and maps its behavior to multiple MITRE ATT&CK techniques, including phishing attachments, DLL injection, and exfiltration over web services. The campaign underscores a broader trend in which ISO files are increasingly abused as a malware delivery vector.

🧠 What Undercode Say: Why This Campaign Signals a Bigger Shift

From an analytical perspective, Operation MoneyMount-ISO is less about novelty and more about precision. The attackers are not chasing mass infections. Instead, they are targeting departments where a single compromised machine can unlock access to payment systems, vendor portals, and internal approval chains.

The use of ISO files is particularly telling. As macro-based documents and executable attachments face stricter filtering, threat actors are pivoting to formats that feel technical but trustworthy. Many finance professionals associate ISO files with enterprise software or secure document delivery, not malware.

Equally important is the linguistic accuracy of the phishing emails. This is not a translated template or a rushed campaign. The Russian business language is formal, context-aware, and tailored to financial workflows. That level of customization suggests reconnaissance and a deep understanding of internal corporate processes.

Phantom Stealer itself reflects modern malware economics. Rather than focusing on persistence alone, it prioritizes rapid data theft and flexible exfiltration. By leveraging platforms like Telegram and Discord, attackers blend malicious traffic into normal organizational noise.

For enterprises, the real risk lies in workflow exploitation. A compromised finance employee does not just lose credentials. They can unknowingly approve fraudulent transfers, expose vendor relationships, or leak documents that enable follow-up attacks.

This campaign also highlights a gap in defensive strategy. Email security tools alone are no longer sufficient. Behavioral monitoring at the memory level, strict attachment execution policies, and enhanced scrutiny of finance-related accounts are becoming mandatory, not optional.

Ultimately, Operation MoneyMount-ISO is a reminder that threat actors evolve alongside defenders. When one door closes, they quietly find another, often hidden behind familiar processes that employees trust every day.

🔍 Fact Checker Results

✅ The campaign and malware attribution are supported by Seqrite Labs analysis.
✅ ISO-based delivery and Phantom Stealer capabilities align with observed threat trends.
❌ No public evidence confirms direct involvement of the impersonated financial brand.

📊 Prediction

📈 ISO-based phishing attachments will continue to rise as attackers evade traditional email filters.
💰 Financial departments will remain high-value targets for credential-stealing malware.
🛡️ Organizations adopting memory-level threat detection will significantly reduce exposure.

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: cyberpress.org
Extra Source Hub (Possible Sources for article):
https://www.discord.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon