PhantomRPC: A new privilege escalation technique in Windows RPC
2026-04-24T08:51:54Z•406edb7602bd1334b27146578fbdb90ecf02cf211ba8c6c0c1bcfb0f8024c7ca
App StoreCVE-2023-32434CVE-2023-38606ClipBankerCorunaCrystalXFakeWalletICSJanelaRATLiteLLMMaaSOperation TriangulationPhantomRPCRATWindows RPCclipboard hijackingcrypto stealerfake RPC serverfinancial threats','phishingiOSindustrial threatskernel exploitprivilege escalationsupply chaintrojanized Proxifier
What happened
Kaspersky Securelist published a series of April 2026 findings covering multiple high‑risk threats and trends: a newly discovered Windows RPC privilege‑escalation technique dubbed PhantomRPC that allows attackers to create fake RPC servers and escalate privileges; over twenty App Store phishing apps distributing the FakeWallet crypto stealer for iOS; an updated Coruna exploit kit for iPhones reusing kernel exploits (CVE-2023-32434 and CVE-2023-38606); a LiteLLM supply‑chain compromise that can exfiltrate data from AI agent deployments; and multiple financial/industrial malware campaigns (Janel
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 406edb7602bd1334b27146578fbdb90ecf02cf211ba8c6c0c1bcfb0f8024c7ca
- Enrichment time
- 2026-04-24T08:51:54Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.