DiscoverDecoded: The Cybersecurity PodcastOperation MoneyMount-ISO: Phantom Stealer Deployment via ISO
Operation MoneyMount-ISO: Phantom Stealer Deployment via ISO

Operation MoneyMount-ISO: Phantom Stealer Deployment via ISO

Update: 2025-12-16
Share

Description

"Operation MoneyMount-ISO," an active cyber campaign originating from Russia that targets finance, accounting, and other related sectors through a sophisticated phishing scheme. The attack begins with a fake bank transfer confirmation email, written in formal Russian, which contains a malicious ZIP file leading to an ISO-mounted executable. This multi-stage infection ultimately deploys the Phantom Stealer malware, a potent information-stealing payload. Seqrite Labs’ research explains the malware’s capabilities, including extensive anti-analysis features, credential harvesting from browsers and crypto wallets, keylogging, clipboard monitoring, and data exfiltration via platforms like Telegram, Discord, and FTP. The operation is noted for its use of ISO mounting to bypass traditional email security controls, reflecting an increasing trend toward more complex initial access techniques for financially motivated cybercrime.

Comments 
In Channel
loading
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

Operation MoneyMount-ISO: Phantom Stealer Deployment via ISO

Operation MoneyMount-ISO: Phantom Stealer Deployment via ISO

Edward Henriquez