PhantomRPC: A new privilege escalation technique in Windows RPC
2026-04-27T08:52:05Z•634be969cdb7b1835dbee20e3aa5c8d181c7e194e84d919acb2f8f1b25d28aba
App Store phishing appsCVE-2023-32434CVE-2023-38606ClipBankerCorunaCrystalXFakeWalletJanelaRATLiteLLMPhantomRPCRATWindows RPCclipper/clipboard hijackercrypto stealerfinancial cyberthreatsiOS exploit kitindustrial automation threatsmalware-as-a-servicephishingprivilege escalationsupply chain attack
What happened
Collection of Kaspersky SecureList posts (Apr 2026) covering multiple active threats and research: a new Windows RPC privilege-escalation technique dubbed PhantomRPC; an App Store campaign distributing FakeWallet crypto stealers; regional financial malware campaigns (JanelaRAT, ClipBanker clipboard hijacker, CrystalX RAT/MaaS); a supply-chain compromise of LiteLLM; an industrial automation threat report for Q4 2025; and the Coruna iPhone exploit framework that reuses/updates kernel exploits (CVE-2023-32434, CVE-2023-38606). The feed highlights supply-chain risk, kernel-level iOS exploits, and广
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 634be969cdb7b1835dbee20e3aa5c8d181c7e194e84d919acb2f8f1b25d28aba
- Enrichment time
- 2026-04-27T08:52:05Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.