PhantomRPC: A new privilege escalation technique in Windows RPC

2026-04-24T20:52:04Z03e87a2a43ce2a5204bd7fdb41b4ae0ca682e4d7b3cdbacab886a2f3696ad94c
App StoreCVE-2023-32434CVE-2023-38606","industrial OT","threat report","Q4 2025","phishClipBankerCorunaCrystalXFakeWalletJanelaRATLiteLLMMaaSOperation TriangulationPhantomRPCProxifierRATRPCWindowsclipboard hijackercrypto stealerfinancial malwareiOSiPhonekernel exploitprivilege escalationsupply chaintrojanized software

What happened

Kaspersky Securelist published a set of mid‑2026 posts covering multiple active threats and research: a newly described PhantomRPC Windows RPC privilege‑escalation technique (fake RPC server), a FakeWallet iOS crypto‑stealer campaign (20+ phishing apps in the App Store), ClipBanker clipboard‑address hijacker delivered via a trojanized Proxifier, JanelaRAT financial campaigns in Latin America, CrystalX RAT offered as MaaS with spyware/stealer/prankware features, a supply‑chain compromise of the LiteLLM gateway, an updated Coruna exploit kit reusing Operation Triangulation iPhone kernel exploits

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
03e87a2a43ce2a5204bd7fdb41b4ae0ca682e4d7b3cdbacab886a2f3696ad94c
Enrichment time
2026-04-24T20:52:04Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · PhantomRPC: A new privilege escalation technique in Windows RPC · Baitaphish