Contents · Introduction · Campaign Overview · Initial Access · Infection Chain · Technical Analysis – Stage 1: Initial Delivery (Archive→JavaScript) – Stage 2: PowerShell Loader1 Analysis – Stage 3: PowerShell Loader2 Analysis – Stage 4 – Phantom Stealer v3.5.0: Data Harvesting and Exfiltration · Campaign Attribution · Conclusion · IOC’s · Seqrite Detection Coverage- · MITRE Attack […] The post Abusing Trusted Business Workflows: A Multi-Stage Phantom Stealer Campaign appeared first on Seqrite Labs.