PhantomRPC: A new privilege escalation technique in Windows RPC
2026-04-24T20:52:04Z•03e87a2a43ce2a5204bd7fdb41b4ae0ca682e4d7b3cdbacab886a2f3696ad94c
App StoreCVE-2023-32434CVE-2023-38606","industrial OT","threat report","Q4 2025","phishClipBankerCorunaCrystalXFakeWalletJanelaRATLiteLLMMaaSOperation TriangulationPhantomRPCProxifierRATRPCWindowsclipboard hijackercrypto stealerfinancial malwareiOSiPhonekernel exploitprivilege escalationsupply chaintrojanized software
What happened
Kaspersky Securelist published a set of mid‑2026 posts covering multiple active threats and research: a newly described PhantomRPC Windows RPC privilege‑escalation technique (fake RPC server), a FakeWallet iOS crypto‑stealer campaign (20+ phishing apps in the App Store), ClipBanker clipboard‑address hijacker delivered via a trojanized Proxifier, JanelaRAT financial campaigns in Latin America, CrystalX RAT offered as MaaS with spyware/stealer/prankware features, a supply‑chain compromise of the LiteLLM gateway, an updated Coruna exploit kit reusing Operation Triangulation iPhone kernel exploits
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 03e87a2a43ce2a5204bd7fdb41b4ae0ca682e4d7b3cdbacab886a2f3696ad94c
- Enrichment time
- 2026-04-24T20:52:04Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.