PhantomRPC: A new privilege escalation technique in Windows RPC

2026-04-24T08:51:54Z406edb7602bd1334b27146578fbdb90ecf02cf211ba8c6c0c1bcfb0f8024c7ca
App StoreCVE-2023-32434CVE-2023-38606ClipBankerCorunaCrystalXFakeWalletICSJanelaRATLiteLLMMaaSOperation TriangulationPhantomRPCRATWindows RPCclipboard hijackingcrypto stealerfake RPC serverfinancial threats','phishingiOSindustrial threatskernel exploitprivilege escalationsupply chaintrojanized Proxifier

What happened

Kaspersky Securelist published a series of April 2026 findings covering multiple high‑risk threats and trends: a newly discovered Windows RPC privilege‑escalation technique dubbed PhantomRPC that allows attackers to create fake RPC servers and escalate privileges; over twenty App Store phishing apps distributing the FakeWallet crypto stealer for iOS; an updated Coruna exploit kit for iPhones reusing kernel exploits (CVE-2023-32434 and CVE-2023-38606); a LiteLLM supply‑chain compromise that can exfiltrate data from AI agent deployments; and multiple financial/industrial malware campaigns (Janel

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
406edb7602bd1334b27146578fbdb90ecf02cf211ba8c6c0c1bcfb0f8024c7ca
Enrichment time
2026-04-24T08:51:54Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.