Phishing Campaign in Russia Deploys Phantom Stealer via ISO Files

Phishing Campaigns Target Russian Finance, HR, and Aerospace Sectors with Advanced Malware and Credential Theft Tools

  • A phishing campaign named Operation MoneyMount-ISO targets Russian finance and accounting sectors using emails with malicious ISO attachments.
  • The Phantom Stealer Malware in the ISO files steals cryptocurrency wallet data, credentials, and monitors user activity, sending stolen data via Telegram or Discord.
  • Another campaign called DupeHike uses phishing emails to deliver DUPERUNNER implant and AdaptixC2 framework to Russian human resources and payroll departments.
  • Multiple phishing operations also exploit Russian finance, legal, and aerospace sectors to deploy Hacking tools like Cobalt Strike, Formbook, and PhantomRemote using compromised company email servers.
  • French Cybersecurity firm attributes cyberattacks on the Russian aerospace industry to Ukrainian-aligned hacktivists using phishing pages hosted on IPFS and Vercel to steal credentials.

Cybersecurity researchers have uncovered ongoing phishing campaigns targeting diverse sectors within Russia, notably finance, accounting, human resources, and aerospace. The campaign known as Operation MoneyMount-ISO, identified by Seqrite Labs, employs phishing emails disguised as payment confirmations. These emails include ZIP attachments containing ISO files, which mount as virtual drives and launch the Phantom Stealer malware. This malware collects sensitive information from cryptocurrency wallets, authentication tokens, passwords, cookies, credit card data, and logs keystrokes. It transmits stolen data via Telegram bots or Discord webhooks, with capabilities to transfer files to FTP servers. Details are available on the Seqrite blog here.

- Advertisement -

Another phishing operation, called DupeHike and linked to a threat group UNG0902, targets Russian human resources and payroll units. It uses emails involving bonus payments to deliver a ZIP file containing decoys and an LNK shortcut file. The LNK downloads the DUPERUNNER implant, which executes the open-source AdaptixC2 command-and-control framework by injecting it into legitimate Windows processes. More information on DupeHike is available from Seqrite here.

Additional spear-phishing campaigns have focused on Russian finance, legal, and aerospace sectors. These deliver malicious tools such as Cobalt Strike, Formbook, DarkWatchman, and PhantomRemote that enable data theft and remote control. The attackers operate by using the email servers of compromised Russian companies to send phishing messages. Further details on these operations can be found at Seqrite here.

A French cybersecurity company, Intrinsec, has linked recent cyberattacks on the Russian aerospace industry to Ukrainian-aligned hacktivists. Detected between June and September 2025, the attacks overlap with known clusters such as Hive0117 and Rainbow Hyena. They use phishing login pages hosted on the InterPlanetary File System (IPFS) and Vercel to steal Microsoft Outlook and company credentials. According to Intrinsec, the efforts target entities collaborating with Russia’s military during ongoing conflict and Western sanctions. More details are provided on Intrinsec’s website here.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -

Latest News

Silver’s rally reignites debate: Bitcoin vs. precious metals

Silver reached a record spot price near $94 per ounce on Monday.Gold climbed to...

Satoshi-era 909 BTC wallet wakes after 13 years, moves $85M.

A Satoshi‑era wallet transferred its full balance of 909.38 BTC—about $84.6 million—after 13 years...

Cardano Volatility Fuels Comeback Hopes After Hoskinson Buzz

Cardano (ADA) trades at $0.36, up 2% in the last 24 hours, after sharp...

Ethereum Leads Bitcoin Liquidations as Macro Headwinds Bite.

Ethereum led crypto liquidations over the last 24 hours, surpassing Bitcoin.Total crypto liquidations totaled...

Bitcoin Falls Amid US-EU Tariff Fears, Drops Near $92K today

Bitcoin traded near $92,000 on Jan. 19 after a weekend decline tied to concerns...
- Advertisement -

Must Read

10 Best Crypto Audiobooks You Don’t Want to Miss

So, you are getting tired of reading books and you want to switch to audiobooks that talk about cryptocurrencies. Well, today we are going...
Bitcoin (BTC) $ 90,783.00 2.57%
Ethereum (ETH) $ 3,091.26 3.75%
XRP (XRP) $ 1.92 2.66%
Bittensor (TAO) $ 239.83 4.41%
Polkadot (DOT) $ 1.98 0.82%
Cardano (ADA) $ 0.358822 2.35%
Chainlink (LINK) $ 12.50 2.49%
Hyperliquid (HYPE) $ 23.01 4.57%
Monero (XMR) $ 584.27 7.85%
Hedera (HBAR) $ 0.107071 2.82%
Toncoin (TON) $ 1.56 3.90%