⤷ Title: Chinese APT Phantom Taurus Targeted MS Exchange Servers Over 3 Years
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Tue, 30 Sep 2025 18:54:31 +0000
════════════════════════
⌗ Tags: #Security #Cyber Attacks #Afghanistan #backdoor #China #Cyber Attack #Cybersecurity #IIServerCore #Malware #Mustang Panda #NET_STAR #Pakistan #Phantom Taurus #Winnti
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Tue, 30 Sep 2025 18:54:31 +0000
════════════════════════
⌗ Tags: #Security #Cyber Attacks #Afghanistan #backdoor #China #Cyber Attack #Cybersecurity #IIServerCore #Malware #Mustang Panda #NET_STAR #Pakistan #Phantom Taurus #Winnti
Hackread
Chinese APT Phantom Taurus Targeted MS Exchange Servers Over 3 Years
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: Phantom Taurus: New Chinese APT Emerges with Fileless NET-STAR Backdoor Targeting Global Governments and Telecoms
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 01 Oct 2025 02:32:34 +0000
════════════════════════
⌗ Tags: #Cyber Security #Chinese APT #Espionage #Fileless Malware #IIS Backdoor #NET_STAR #Phantom Taurus #Telecommunications #Unit 42
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 01 Oct 2025 02:32:34 +0000
════════════════════════
⌗ Tags: #Cyber Security #Chinese APT #Espionage #Fileless Malware #IIS Backdoor #NET_STAR #Phantom Taurus #Telecommunications #Unit 42
Daily CyberSecurity
Phantom Taurus: New Chinese APT Emerges with Fileless NET-STAR Backdoor Targeting Global Governments and Telecoms
Unit 42 uncovers Phantom Taurus, a new Chinese APT using the fileless NET-STAR backdoor to target SQL databases and IIS servers in global espionage campaigns.
⤷ Title: Phantom Taurus: New Chinese APT Emerges with Fileless NET-STAR Backdoor Targeting Global Governments and Telecoms
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 02 Oct 2025 03:24:32 +0000
════════════════════════
⌗ Tags: #Cyber Security #Chinese APT #Espionage #Fileless Malware #IIS Backdoor #NET_STAR #Phantom Taurus #Telecommunications #Unit 42
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 02 Oct 2025 03:24:32 +0000
════════════════════════
⌗ Tags: #Cyber Security #Chinese APT #Espionage #Fileless Malware #IIS Backdoor #NET_STAR #Phantom Taurus #Telecommunications #Unit 42
Penetration Testing Tools
Phantom Taurus: New Chinese APT Emerges with Fileless NET-STAR Backdoor Targeting Global Governments and Telecoms
Unit 42 uncovers Phantom Taurus, a new Chinese APT using the fileless NET-STAR backdoor to target SQL databases and IIS servers in global espionage campaigns.
⤷ Title: PassiveNeuron Cyberespionage Resurfaces: APT Abuses MS SQL Servers to Deploy Stealthy Neursite Backdoor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 00:26:39 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #Asia #Cyberespionage #MsSQL #NeuralExecutor #Neursite #PassiveNeuron #Phantom DLL Hijacking
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 00:26:39 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #Asia #Cyberespionage #MsSQL #NeuralExecutor #Neursite #PassiveNeuron #Phantom DLL Hijacking
Daily CyberSecurity
PassiveNeuron Cyberespionage Resurfaces: APT Abuses MS SQL Servers to Deploy Stealthy Neursite Backdoor
Kaspersky exposed the resurfaced PassiveNeuron campaign targeting Asia via MS SQL servers. The APT deploys custom Neursite and NeuralExecutor backdoors using Phantom DLL Hijacking for stealth persistence.
⤷ Title: Phantom Stealer Targets Russian Finance with ISO Phishing, Deploying Keyloggers and Crypto-Wallet Theft
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:27:19 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Crypto theft #Financial Sector #information stealer #ISO File #Keylogger #Phantom Stealer #phishing #russia #social engineering
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:27:19 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Crypto theft #Financial Sector #information stealer #ISO File #Keylogger #Phantom Stealer #phishing #russia #social engineering
Daily CyberSecurity
Phantom Stealer Targets Russian Finance with ISO Phishing, Deploying Keyloggers and Crypto-Wallet Theft
Operation MoneyMount-ISO targets Russian financial institutions with a Phantom Stealer info-stealer hidden in an ISO file. The malware steals crypto wallets, browser data, and uses a keylogger. It has a SelfDestruct function for evasion.
⤷ Title: The Ghost in the Machine: Operation MoneyMount-ISO Uses Fake Payment Lures to Unleash Phantom Stealer
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 04:38:51 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Data Exfiltration #Discord Webhooks #Financial Cybercrime #Info_stealer #ISO Malware #Operation MoneyMount_ISO #Phantom Stealer #phishing campaign #Seqrite Labs #Telegram Bot
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 04:38:51 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Data Exfiltration #Discord Webhooks #Financial Cybercrime #Info_stealer #ISO Malware #Operation MoneyMount_ISO #Phantom Stealer #phishing campaign #Seqrite Labs #Telegram Bot
Penetration Testing Tools
The Ghost in the Machine: Operation MoneyMount-ISO Uses Fake Payment Lures to Unleash Phantom Stealer
While monitoring digital threat activity, researchers at Seqrite Labs uncovered a new targeted campaign dubbed Operation MoneyMount-ISO. The
⤷ Title: Phantom v3.5 Alert: New Info-Stealer Disguised as Adobe Update Uses SMTP to Loot Digital Lives
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 00:11:31 +0000
════════════════════════
⌗ Tags: #Malware #Adobe Installer #Credential Theft #crypto wallet #info_stealer #JavaScript malware #K7 Security Labs #malware #Phantom Stealer #powershell #SMTP Exfiltration
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 00:11:31 +0000
════════════════════════
⌗ Tags: #Malware #Adobe Installer #Credential Theft #crypto wallet #info_stealer #JavaScript malware #K7 Security Labs #malware #Phantom Stealer #powershell #SMTP Exfiltration
Daily CyberSecurity
Phantom v3.5 Alert: New Info-Stealer Disguised as Adobe Update Uses SMTP to Loot Digital Lives
Phantom v3.5 info-stealer targets passwords and crypto via a fake Adobe installer. It uses SMTP to exfiltrate data directly to attackers.
⤷ Title: Signed & Stolen: “Phantom Stealer” Hijacks Java App via Fake DHL Invoice
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:36:35 +0000
════════════════════════
⌗ Tags: #Malware #AddInProcess32.exe #DHL Phishing #DLL Sideloading #info_stealer #Java security #jdeps.exe #Malware Analysis #Manoj Kshirsagar #Phantom Stealer #Process Hollowing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:36:35 +0000
════════════════════════
⌗ Tags: #Malware #AddInProcess32.exe #DHL Phishing #DLL Sideloading #info_stealer #Java security #jdeps.exe #Malware Analysis #Manoj Kshirsagar #Phantom Stealer #Process Hollowing
Daily CyberSecurity
Signed & Stolen: "Phantom Stealer" Hijacks Java App via Fake DHL Invoice
Attackers use fake DHL invoices to sideload Phantom Stealer v3.5.0 via a signed Java utility. Malware hides in AddInProcess32.exe. Watch out.
⤷ Title: “Hard Working” Thieves: Rublevka Team Steals $10M in Solana Scam-as-a-Service
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Feb 2026 00:17:18 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Crypto theft #Cybercrime #Insikt Group #Phantom Wallet #Rublevka Team #Scam_as_a_Service #social engineering #Solana #TON #Wallet drainer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Feb 2026 00:17:18 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Crypto theft #Cybercrime #Insikt Group #Phantom Wallet #Rublevka Team #Scam_as_a_Service #social engineering #Solana #TON #Wallet drainer
Daily CyberSecurity
"Hard Working" Thieves: Rublevka Team Steals $10M in Solana Scam-as-a-Service
Rublevka Team's "scam-as-a-service" has stolen $10M+ in crypto. Their automated Solana drainers target Phantom & Solflare wallets. Don't be next.
⤷ Title: The Phantom Menace: Unmasking 0APT’s Trillion-Byte Bluff in the 2026 Ransomware Scene
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 16 Feb 2026 15:56:25 +0000
════════════════════════
⌗ Tags: #Malware #0APT #Cyber Security #Data Exfiltration #Digital Extortion #Intel 471 #phantom threat #RaaS #Ransomware_as_a_Service #Tech News 2026 #threat intelligence
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 16 Feb 2026 15:56:25 +0000
════════════════════════
⌗ Tags: #Malware #0APT #Cyber Security #Data Exfiltration #Digital Extortion #Intel 471 #phantom threat #RaaS #Ransomware_as_a_Service #Tech News 2026 #threat intelligence
Penetration Testing Tools
The Phantom Menace: Unmasking 0APT’s Trillion-Byte Bluff in the 2026 Ransomware Scene
In the nascent weeks of 2026, a formidable new antagonist emerged within the digital theater: a collective identifying
⤷ Title: Microsoft Smashes “Fox Tempest” Cyber Syndicate Selling Cryptographic Cover for Ransomware
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 21 May 2026 07:17:59 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Code Validation Bypass #Fox Tempest Malware Signing #Malvertising SEO Poisoning #Microsoft Artifact Signing Abuse #OpFauxSign Takedown #Phantom Azure Developer Tenancies #Rhysida Ransomware Deployment #Short_Lived 72_Hour Certificates #SignSpace Cloud Seizure #Vanilla Tempest Co_Conspirator
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 21 May 2026 07:17:59 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Code Validation Bypass #Fox Tempest Malware Signing #Malvertising SEO Poisoning #Microsoft Artifact Signing Abuse #OpFauxSign Takedown #Phantom Azure Developer Tenancies #Rhysida Ransomware Deployment #Short_Lived 72_Hour Certificates #SignSpace Cloud Seizure #Vanilla Tempest Co_Conspirator
Penetration Testing Tools
Microsoft Smashes "Fox Tempest" Cyber Syndicate Selling Cryptographic Cover for Ransomware
Microsoft has initiated formal civil litigation against the fraudulent syndicate operating the Fox Tempest enterprise, an illicit infrastructure
⤷ Title: Phantom Squatting Attacks Weaponize AI Hallucinated Domains, Unit 42 Warns
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 08 Jul 2026 08:13:32 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI security #LLM Hallucination #Phantom Squatting #phishing #Unit 42
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 08 Jul 2026 08:13:32 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI security #LLM Hallucination #Phantom Squatting #phishing #Unit 42
Daily CyberSecurity
Phantom Squatting Attacks Weaponize AI Hallucinated Domains, Unit 42 Warns
At a glance Details Activity type Phantom squatting: registering AI hallucinated domains for phishing and malware Actors Multiple suspected threat actors, including the “Montana Empire”…