PhantomRPC: A new privilege escalation technique in Windows RPC

2026-04-27T08:52:05Z634be969cdb7b1835dbee20e3aa5c8d181c7e194e84d919acb2f8f1b25d28aba
App Store phishing appsCVE-2023-32434CVE-2023-38606ClipBankerCorunaCrystalXFakeWalletJanelaRATLiteLLMPhantomRPCRATWindows RPCclipper/clipboard hijackercrypto stealerfinancial cyberthreatsiOS exploit kitindustrial automation threatsmalware-as-a-servicephishingprivilege escalationsupply chain attack

What happened

Collection of Kaspersky SecureList posts (Apr 2026) covering multiple active threats and research: a new Windows RPC privilege-escalation technique dubbed PhantomRPC; an App Store campaign distributing FakeWallet crypto stealers; regional financial malware campaigns (JanelaRAT, ClipBanker clipboard hijacker, CrystalX RAT/MaaS); a supply-chain compromise of LiteLLM; an industrial automation threat report for Q4 2025; and the Coruna iPhone exploit framework that reuses/updates kernel exploits (CVE-2023-32434, CVE-2023-38606). The feed highlights supply-chain risk, kernel-level iOS exploits, and广

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
634be969cdb7b1835dbee20e3aa5c8d181c7e194e84d919acb2f8f1b25d28aba
Enrichment time
2026-04-27T08:52:05Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · PhantomRPC: A new privilege escalation technique in Windows RPC · Baitaphish