Phantom Stealer Hides in PNG Files, Steals Passwords and Crypto

Phantom Stealer malware uses PNG images to hide its payload and steal passwords and cryptocurrency from Windows systems.

By Central
Phantom Stealer is a multi-stage malware that hides encrypted payloads inside PNG images to bypass security scans.
Highlights
  • Phantom Stealer uses PNG steganography to embed its malicious payload within seemingly benign image files.
  • The malware's modular design and multi-stage attack chain make it versatile and dangerous for cybercriminals.
  • Defenders should watch for unexpected PNG resources with script activity as indicators of process injection.

In the evolving arms race between cybercriminals and defenders, the most unassuming file formats are increasingly weaponized. The humble PNG image, a staple of digital life, has become a perfect hiding place for a new credential and cryptocurrency thief known as Phantom Stealer. This .NET-based malware employs steganography—the practice of concealing data within other files—to embed its malicious payload directly into seemingly benign image resources. By hiding in plain sight, it can bypass many initial security scans, establishing a foothold on a Windows machine with the ultimate goal of stealing passwords, browser cookies, and cryptocurrency wallet data. Its modular design and multi-stage attack chain make it a versatile and dangerous tool for both novice and experienced cybercriminals, leveraging phishing emails, pirated software, and social engineering on platforms like Discord and Telegram to find its victims.

How Phantom Stealer Uses PNG Steganography to Evade Detection

The core innovation of Phantom Stealer is its use of steganography, a technique where secret data is hidden within an ordinary, non-secret file or message. In the attack chains observed by Splunk researchers, the threat uses PNG image files as a vessel. The image itself may be visually unremarkable. However, within the file’s resource section, an encrypted payload waits to be extracted. This approach is not entirely novel, echoing previous campaigns such as those involving XWorm, but the sophistication and modularity of this particular stealer raise the stakes significantly.

In one specific infection chain described by Splunk, a .NET loader acts as the first stage. This loader contains a PNG file within its own internal resources. The PNG file is not the initial infection vector but serves as a storage container for the next stage. The data hidden inside the PNG is encrypted. The loader’s primary job is to decrypt this concealed data, revealing the Phantom Stealer executable only after the initial loader has already been running. This multi-step decryption complicates static file analysis; a simple scan of the loader or the PNG file alone may reveal nothing malicious.

A second, more sophisticated loader variant arrives via phishing emails, often as a heavily obfuscated PowerShell script. This script is designed to decrypt its code and then inject it into a legitimate Windows process, commonly explorer.exe. Operating from within a trusted, signed system process allows the malware to blend into normal system activity, effectively reducing the visibility of its actions to security monitoring tools. It can then unpack the final stealer payload, disabling or interfering with Windows security features like Event Logging and Windows Defender to cement its persistence.

Splunk research illustrating the extraction of next-stage payloads hidden within two PNG image files.
Phantom Stealer Steganography Loader Extraction (Source – Splunk)

figurefigurefigure

The practical lesson for defenders is clear: while a picture file alone is not proof of danger, any unexpected image resource paired with script activity or suspicious process injection deserves immediate and thorough investigation. The use of steganography requires a deep inspection of file contents, not just a superficial check of file extensions or metadata.

Phantom Stealer’s Target: Passwords, Cookies, and Cryptocurrency Wallets

Once the Phantom Stealer payload is fully active and resident in memory, it begins its primary mission: systematic data theft. Its modular architecture allows it to target a wide range of sensitive information, but its focus is squarely on credentials, authentication tokens, and financial assets.

The malware searches the file systems and configuration databases of major web browsers, including Chrome, Firefox, Edge, and Brave. It extracts saved usernames and passwords, complete browser profiles, stored autofill data including payment card information, and—critically—cookies. The targeting of cookies is a particularly potent threat because they represent an authenticated session. An attacker can import a stolen cookie into their own browser and gain immediate, password-free access to a victim’s online accounts, including email, social media, cloud services, and corporate portals. This technique bypasses even multi-factor authentication, which only protects the login step itself, not the subsequent session token. The risk of browser session theft is so severe that any cookie leakage should be treated as a full account takeover.

Beyond the browser, Phantom Stealer demonstrates a clear focus on cryptocurrency. It copies data from cryptocurrency wallet browser extensions and dedicated desktop wallet applications. It actively monitors the system clipboard, looking for cryptocurrency wallet addresses. When a user copies a wallet address for a transaction—for example, to send Bitcoin or Ethereum to a vendor—the malware swaps it with an attacker-controlled address. The victim then unknowingly pastes the criminal’s address, sending their payment directly into the thief’s wallet. This clipboard hijacking is a simple but devastatingly effective technique for intercepting transactions.

What Data Does Phantom Stealer Collect?

The malware’s data collection scope is extensive, extending far beyond browsers and wallets. Splunk researchers documented its ability to seek out and exfiltrate data from a wide array of system targets. This includes, but is not limited to, specific document files and local databases, login credentials for FileZilla and WinSCP (tools often used by system administrators and developers), Outlook profile information, and data from instant messaging applications. It can capture screenshots of the active desktop, log keystrokes entered by the user, and even steal saved Wi-Fi network profiles from the system. This comprehensive collection makes it a highly effective espionage tool, capable of gathering both personal and operational data.

How Phantom Stealer Maintains Persistence on a System

To ensure its survival after a system reboot—a critical capability for any successful malware—Phantom Stealer establishes persistence. It creates a Registry Run entry, which automatically launches the malware every time the user logs into Windows. As a backup or alternative method, it may also place a shortcut or file in the Windows Startup folder. This dual-pronged persistence strategy makes manual removal more difficult, as tampering with one method may still leave the other in place. Before it begins the process of theft, the malware also conducts a thorough check of the system environment. It inspects the operating system version, system architecture, installed hardware, and running processes for signs that it is running inside a sandbox, virtual machine, or debugging environment. If it detects any such analysis indicators, it can slow its operations or halt execution entirely to avoid detection. This anti-analysis capability means that a negative test result from a security vendor should not be treated as conclusive, especially if the sample has not waited long enough to pass the malware’s timers.

IoCs and Defensive Strategies Against Phantom Stealer

For security teams and threat intelligence analysts, the following indicators of compromise (IoCs) have been identified by Splunk in association with Phantom Stealer campaigns. These hashes can be used to search for the malware’s presence within an environment.

Indicators of Compromise (IoCs)

The IoCs are presented as SHA-256 hashes, network indicators are defanged (e.g., [.]codecodecode) to prevent accidental resolution. They should be re-fanged only within controlled threat intelligence platforms like MISP, VirusTotal, or your SIEM.

Type Indicator Description
SHA-256 b588caa5365451a6c60fd73fec5b73f13ac41bcc2a3a3bed7244df5917a62f32codecodecode Phantom Stealer Loader; Phantom Stealer PowerShell Loader
SHA-256 382233c398cbc35dcee845ee17046815f37588a382a8106bfb9b0252ea803961codecodecode Phantom Stealer Batch Loader
SHA-256 790945e17a51691483455a11af2efcbe15f2b473b65b151f50287623d1468516codecodecode Phantom Stealer
SHA-256 01f1e5369aa0332abb681df7c37818e197ec0a5b5d7b81836b3369a2b1780950codecodecode Phantom Stealer
SHA-256 10cfcad907275497dab92af0d687674cec3a0333f80dd16d8d22254794bb2d60codecodecode Phantom Stealer
SHA-256 2d5003d9318ae85eb22de99d19705a3cd7bf8e5c3349df979dfb3bdfa080908ecodecodecode Phantom Stealer
SHA-256 528a46842744366b57edfc6fe2810ca7df43900db75126cd1c78f32957143364codecodecode Phantom Stealer
SHA-256 e3ceeb24bdca8842d426e87fa61cf185d68fd7783e1a2b97d4106832ca266724codecodecode Phantom Stealer
SHA-256 f82a4d30132b5a57cbfd81c7ab0a53d0cf0dda402c2731732a0097aceb4b0b76codecodecode Phantom Stealer
SHA-256 be119a21bedc3a79bf4dea8bcf5adf18304997a01ea23e276b9c31be37b789abcodecodecode Phantom Stealer JavaScript Loader

What Should Defenders Look For?

To protect against Phantom Stealer and its variants, security teams should actively monitor for the following behavioral indicators that fall squarely into the malware’s operational pattern. Unusual PowerShell activity, particularly scripts that decode base64 or other obfuscated content from memory or the local file system, should be treated with a high degree of suspicion. The detection of a process (like explorer.execodecodecode) writing to another process or creating a remote thread in a non-standard process is a red flag for process injection. Additionally, security teams should issue alerts when a non-browser application, such as a PowerShell script or a .NET executable, attempts to read the database files or registry keys of a web browser (e.g., Login Datacodecodecode, Cookiescodecodecode, Web Datacodecodecode). A browser process being launched with a custom --user-data-dircodecodecode parameter, or the insecure --no-sandboxcodecodecode flag, is a strong indicator of malicious intent.

The emergence of Phantom Stealer serves as a critical reminder that no file format can be implicitly trusted. The attack chain illustrates how a simple-looking PNG file can be the linchpin in a sophisticated credential theft operation. The modularity of the malware reduces the barrier to entry for cybercriminals, widening the pool of potential attackers who can deploy it. The threat is global, with campaigns observed targeting users across several countries, using distribution channels that range from professional phishing lures to casual offers for pirated software on Discord. For individual users, the lessons are clear: avoid downloading software from unverified sources, treat unsolicited email attachments with extreme skepticism, and enable multi-factor authentication wherever possible. For organizations, the combination of process injection, steganography, and a comprehensive credential theft module demands a layered security strategy that includes strong endpoint detection and response (EDR) systems, user behavior analytics (UBA), and rigorous threat hunting for anomalous process and browser behavior. A stolen PNG file is no longer just a broken graphic; it can be a gateway to a complete digital identity takeover.

Share This Article