Full Report
Key Takeaways
Analysis Summary
# Tool/Technique: PhantomPolia & Remus Stealer
## Overview
This entry describes a multi-stage infection chain observed in late 2026. The campaign utilizes a sophisticated JavaScript loader named **PhantomPolia** that leverages Web3 technology (Ethereum smart contracts) as a dead-drop resolver. The final objective is the delivery of **Remus Stealer**, a modular info-stealer, via a "ClickFix" social engineering lure and Donut-packed shellcode.
## Technical Details
- **Type:** Malware Family (Stealer) / Loader (PhantomPolia)
- **Platform:** Windows
- **Capabilities:** Smart contract-based C2 resolution, credential theft, crypto-wallet hijacking, and defense evasion via Donut shellcode.
- **First Seen:** September 2026
## MITRE ATT&CK Mapping
- **[TA0001 - Initial Access]**
- [T1189 - Drive-by Compromise]
- **[TA0002 - Execution]**
- [T1059.001 - PowerShell]
- [T1059.007 - JavaScript]
- **[TA0005 - Defense Evasion]**
- [T1027 - Obfuscated Files or Information]
- [T1140 - Deobfuscate/Decode Files or Information]
- [T1497 - Virtualization/Sandbox Evasion]
- **[TA0007 - Discovery]**
- [T1082 - System Information Discovery]
- [T1016 - System Network Configuration Discovery]
- **[TA0009 - Collection]**
- [T1555 - Credentials from Password Stores]
- **[TA0011 - Command and Control]**
- [T1102.001 - Dead Drop Resolver (Smart Contract)]
## Functionality
### Core Capabilities
- **Dead-Drop Resolution:** PhantomPolia uses the `Ethers.js` library to query an Ethereum Sepolia smart contract (`getText()`) to retrieve encrypted C2 configuration.
- **Data Exfiltration:** Remus Stealer targets browser data, password managers, and cryptocurrency wallets.
- **Stealthy Execution:** Uses AutoIt scripts to decrypt and inject Donut-packed shellcode directly into memory.
### Advanced Features
- **Blockchain C2:** By using public RPC endpoints (e.g., `0xrpc[.]io`), the malware avoids hardcoding C2 domains in the initial script, making static analysis and domain blocking more difficult.
- **Custom Encryption:** Stolen data is compressed using a custom method and encrypted with **ChaCha20** before exfiltration.
- **Cryptographic Obfuscation:** Uses PBKDF2 with 100,000 iterations and AES-GCM for stage-one configuration decryption.
## Indicators of Compromise
- **File Names:** `update.ps1`, `redmast.js`
- **Network Indicators:**
- `hxxps://0xrpc[.]io/sep` (RPC Endpoint)
- `hxxps://1rpc[.]io/sepolia` (RPC Endpoint)
- `hxxps://cdn.jsdelivr[.]net/npm/[email protected]/dist/ethers.esm.js` (Dependency)
- `0x5a3589462b41fa8cF91ac2C7773A285d9c790548` (Sepolia Contract Address)
- **Behavioral Indicators:**
- PowerShell execution with `-w h -ep bypass` flags.
- Unexpected calls to Ethereum RPC nodes from non-developer workstations.
- AutoIt processes allocating `PAGE_EXECUTE_READWRITE` memory.
## Associated Threat Actors
- **PhantomPolia / ClickFix Operators:** Specific group attribution is currently linked to broad "ClickFix" campaign actors.
## Detection Methods
- **Signature-based:** Detect `Ethers.js` usage in unusual JavaScript contexts on compromised websites.
- **Behavioral:** Monitor for `PowerShell.exe` making outbound requests to remote domains to fetch `.ps1` files.
- **Network:** Alert on traffic to public Ethereum RPC providers from general user segments.
## Mitigation Strategies
- **Content Filtering:** Block known public Ethereum RPC endpoints if not required for business operations.
- **Scripting Restrictions:** Enforce Constrained Language Mode for PowerShell and restrict the execution of unsigned scripts.
- **Endpoint Hardening:** Disable or monitor AutoIt executable activity and utilize ASR (Attack Surface Reduction) rules to block process injections.
## Related Tools/Techniques
- **Donut:** A shellcode generation tool used to create position-independent code from .NET assemblies/PE files.
- **ClickFix:** A common social engineering technique where users are told their browser is broken and are instructed to paste a command into a terminal to "fix" it.
- **ClearFake:** A similar campaign structure using fake updates and social engineering.