
A multi-stage phishing campaign impersonates UPS and Malaysia’s Inland Revenue Board to deploy Phantom Stealer v3.5.0, a malware that steals credentials and data. The attack uses obfuscated JavaScript and PowerShell scripts to evade detection and exfiltrates data via SMTP. Seqrite documented the campaign, which targets procurement and finance teams with fake shipment and tax audit emails. Organizations should monitor for anomalous outbound SMTP traffic and restrict script execution to mitigate such threats.