Fileless Phantom Stealer Targets Browser Credentials

2026-06-17T02:51:43Ze74ba5d5ce30bfb9e4e2b28053a431c7cfbd9e21ee6dd7388a3063b2bfadd3b6
AI security risks and export controls (Anthropic)Android trojanClickFix deliveryCopilot/SearchLeak prompt injectionEDR evasionFishMongerGitHub supply chainHTTP/2 amplification DoSIronWormMiasmaNPMPyPIRokarollaSprySOCKSWordPress compromiseanti-analysisbrowser credential stealercredential theftfileless malwarekernel driver abusememory-only malwarepersistenceransomware/vice societyremote accesssupply chain compromise

What happened

A broad set of active and emerging threats affecting enterprise, cloud and consumer environments: a fileless 'Phantom' stealer runs entirely in memory to harvest browser credentials and uses anti-analysis techniques; a SprySOCKS Windows variant abuses kernel drivers and other EDR-evasion methods; Rokarolla Android trojan increases device takeover, persistence and surveillance; supply-chain campaigns (Miasma, IronWorm, Hades/Shai‑Hulud) target developer ecosystems (GitHub, NPM, PyPI); multiple zero-days and actively exploited flaws hit Oracle, Ivanti Sentry, Check Point VPN and WinRAR (CVE-2025

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
e74ba5d5ce30bfb9e4e2b28053a431c7cfbd9e21ee6dd7388a3063b2bfadd3b6
Enrichment time
2026-06-17T02:51:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.