Phantom Stealer Malware Hides Inside PNG Files to Steal Passwords, Cookies and Crypto
A newly documented malware strain called Phantom Stealer is exploiting a familiar file format — the PNG image — as a hiding place for its malicious payload. Once deployed on Windows systems, the malware quietly collects passwords, browser cookies, cryptocurrency wallet material and other sensitive data from infected machines. Researchers say the threat has already appeared in active campaigns targeting users across multiple countries.
Phantom Stealer uses a technique known as steganography, concealing its next-stage payload inside PNG resource files. By embedding malicious code within what appears to be an ordinary image, the malware is able to evade detection tools that might otherwise flag suspicious executables or scripts. The approach is a variation of a broader trend in which threat actors abuse legitimate file formats to smuggle malware past security controls.
Once the hidden payload is extracted and executed on a victim’s machine, Phantom Stealer proceeds to harvest a wide range of valuable information. Targeted data includes saved credentials from browsers, session cookies that can be used to hijack online accounts without needing a password, and files associated with cryptocurrency wallets — making it a significant threat to both general users and those holding digital assets. The combination of credential theft and cookie harvesting means attackers can potentially gain access to email accounts, financial services and other sensitive platforms even when multi-factor authentication is in place, since stolen session cookies can bypass login prompts entirely.
The malware’s focus on Windows systems and its deployment across multiple countries suggests an organized campaign rather than opportunistic infections. While the full scope of affected regions has not been detailed, the international reach indicates the operators behind Phantom Stealer are actively distributing it at scale. Security researchers recommend users keep endpoint protection software updated, exercise caution with downloaded files regardless of their apparent format, and regularly audit browser-saved credentials and active sessions.
The emergence of Phantom Stealer underscores a persistent challenge for defenders: as security tools improve at detecting malicious executables, attackers continue to adapt by hiding payloads in unexpected places, including image files that most users and some automated systems treat as inherently safe.