CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back ◇ Industry News & Leadership Aug 13, 2026

Phantom Stealer Hides Inside PNG Files, Then Steals Your Passwords, Cookies and Crypto

Cybersecurity News Archived Aug 13, 2026 ✓ Full text saved

Phantom Stealer is taking a familiar computer file and turning it into a hiding place. The credential-stealing malware can conceal its next stage in PNG resources, then quietly collect passwords, browser cookies, cryptocurrency wallet material and other valuable data from Windows systems. The threat has appeared in campaigns aimed at users in several countries. Its […] The post Phantom Stealer Hides Inside PNG Files, Then Steals Your Passwords, Cookies and Crypto appeared first on Cyber Security

Full text archived locally
✦ AI Summary · Claude Sonnet


    HomeCyber Security News Phantom Stealer Hides Inside PNG Files, Then Steals Your Passwords, Cookies and Crypto By Tushar Subhra Dutta August 13, 2026 Phantom Stealer is taking a familiar computer file and turning it into a hiding place. The credential-stealing malware can conceal its next stage in PNG resources, then quietly collect passwords, browser cookies, cryptocurrency wallet material and other valuable data from Windows systems. The threat has appeared in campaigns aimed at users in several countries. Its operators use phishing emails, pirated software and malicious links circulated through Discord and Telegram, making an infection possible wherever a tempting download or message gets a click. Analysts at Splunk identified the malware as a .NET-based stealer with a modular design that can help both less experienced and established criminals deploy it. That flexibility raises the stakes: stolen session cookies can let an intruder enter an account without knowing the password, while wallet data can lead directly to financial loss. Splunk said in a report shared with Cyber Security News (CSN) that the malware can stay hidden, keep access after a restart, and gather browser, wallet, file and clipboard data. Its use of image-borne payloads also echoes recent PNG steganography campaigns, where normal-looking graphics carry code that scanners may overlook. Phantom Stealer Hides Inside PNG Files The PNG file is not necessarily the item that starts the infection. In one observed chain, a .NET loader stores an executable in a PNG entry within its own resources. The concealed data is encrypted, and the loader decrypts it to reveal Phantom Stealer only after it has started, frustrating quick file inspection. That approach is called steganography, meaning information is hidden inside an ordinary-looking file. It is particularly useful because image files are common and often trusted. Readers may recall earlier image hiding attacks, which similarly used encrypted material disguised as PNG content. Another loader arrived through a phishing email as a heavily obscured PowerShell script. It decrypted code and placed it inside explorer.exe, a normal Windows process. From there, it can unpack the final stealer and weaken visibility by interfering with Windows security scanning and event logging. Phantom Stealer Steganography Loader Extraction (Source – Splunk) The supplied research illustrates extraction of the next-stage content hidden in two image files. The practical lesson is simple: a picture file alone is not proof of danger, but unexpected image resources paired with script activity deserve close review. Passwords, Cookies And Crypto At Risk Once active, Phantom Stealer searches browser databases and configuration files for saved usernames, passwords, profiles, cookies and payment-card data. Cookies matter because they can preserve an authenticated web session. This makes browser session theft risks a concern even for people who use multi-factor authentication. The malware also copies data from cryptocurrency wallet browser extensions and desktop wallet applications. It watches the clipboard, looking for wallet addresses. Extracted Phantom Stealer Payload (Source – Splunk) When it finds one, it can replace the copied address with an attacker-controlled value, potentially sending a payment to the wrong recipient when the victim pastes it. Its reach extends beyond browsers. Researchers observed it seeking selected documents and databases, FileZilla settings, saved WinSCP credentials, Outlook profile information, screenshots, typed keystrokes and saved Wi-Fi profiles. It can create a Registry Run entry or use the Startup folder so it launches again after reboot. Before stealing data, it checks system, account, processes, services and network details for signs it is inside a sandbox. It can slow or halt when it suspects analysis. This means a test result should not be treated as final, especially when a sample has not completed timing checks. It starts Chrome with command line settings to isolate work from the victim’s browser session. Defenders should investigate unusual PowerShell activity, remote process injection, non-browser programs accessing browser data, and browsers launched with a custom user-data directory or no-sandbox setting. Security teams should also inspect suspicious downloads and email attachments, block unauthorized software, and rotate passwords, sessions and wallet credentials after a confirmed infection. Similar crypto wallet targeting tactics show why affected assets should be treated as exposed immediately. Indicators of compromise (IoCs):- Type Indicator Description SHA-256 b588caa5365451a6c60fd73fec5b73f13ac41bcc2a3a3bed7244df5917a62f32 Phantom Stealer Loader; Phantom Stealer PowerShell Loader SHA-256 382233c398cbc35dcee845ee17046815f37588a382a8106bfb9b0252ea803961 Phantom Stealer Batch Loader SHA-256 790945e17a51691483455a11af2efcbe15f2b473b65b151f50287623d1468516 Phantom Stealer SHA-256 01f1e5369aa0332abb681df7c37818e197ec0a5b5d7b81836b3369a2b1780950 Phantom Stealer SHA-256 10cfcad907275497dab92af0d687674cec3a0333f80dd16d8d22254794bb2d60 Phantom Stealer SHA-256 2d5003d9318ae85eb22de99d19705a3cd7bf8e5c3349df979dfb3bdfa080908e Phantom Stealer SHA-256 528a46842744366b57edfc6fe2810ca7df43900db75126cd1c78f32957143364 Phantom Stealer SHA-256 e3ceeb24bdca8842d426e87fa61cf185d68fd7783e1a2b97d4106832ca266724 Phantom Stealer SHA-256 f82a4d30132b5a57cbfd81c7ab0a53d0cf0dda402c2731732a0097aceb4b0b76 Phantom Stealer SHA-256 be119a21bedc3a79bf4dea8bcf5adf18304997a01ea23e276b9c31be37b789ab Phantom Stealer JavaScript Loader Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM. Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world Tags cyber security cyber security news Copy URL Linkedin Twitter ReddIt Telegram Tushar Subhra Dutta Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics. Cyber Security Guide Top 10 Malware Threats of the Week – AsyncRAT, Remcos, and Xworm Lead the Surge Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA How Top SOCs Detect and Stop AI Phishing that Beats Email Gateways  Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026) An SOC Story of Why Fast Answers Beat Perfect Answers in Cyber Incident Response  Latest Cyber News Adobe Critical Adobe Commerce Vulnerabilities Allows Hackers to Execute Arbitrary Code Cyber Security Cisco Firewall 0-Day Vulnerability Exploited in the Wild to Trigger DoS Condition Cyber Security Critical WordPress RCE Vulnerability Allows Authors to Execute Code via Malicious PNG File Cyber Security News Palo Alto Networks Patches 11 New Vulnerabilities Across PAN-OS, GlobalProtect, and Prisma Access Cyber Attack News New “City-Forum” Hackers Attacking Salesforce and ServiceNow Instances Worldwide Expert Talks Expert Talks From Reactive Forensics to Predictive Defence: Strengthening Cyber Resilience in Banking  Expert Talks Beyond the Lure: What the DoNot Campaign Reveals About Modern Cyber Espionage  Expert Talks Your Incident Response Plan Has a Dependency You Never Approved Expert Talks Security in the AI Era Starts with First Principles  Cyber Security News Planning Your AI Security – How will You Manage All Your Resources?
    💬 Team Notes
    Article Info
    Source
    Cybersecurity News
    Category
    ◇ Industry News & Leadership
    Published
    Aug 13, 2026
    Archived
    Aug 13, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗