INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Lazarus Group Bundles Infostealer, Crypter and RAT for Sale

| 2026-03-31 14:00 LOW HIGH DATA BREACH MALWARE & BOTNETS
Executive Summary
AI-generated
A sustained phishing campaign delivering Phantom Stealer, a .NET-based infostealer that collects sensitive information from infected systems, targeted organizations in the logistics, manufacturing and technology sectors across Europe between November 2025 and January 2026. The attackers impersonated a legitimate equipment trading company using procurement-related subject lines designed to resemble business correspondence, with phishing emails blocked before reaching end users. The campaign occurred in five waves, utilizing automated tooling and template reuse, including spoofed business identity and rotating infrastructure. Cybersecurity researchers detected the campaign through layered analysis combining sender authentication checks, content analysis and malware detonation in a controlled environment, confirming credential harvesting, anti-analysis techniques and data exfiltration behavior.
Technical Mitigations AI-generated
• Use SPF authentication and DKIM signatures to prevent phishing emails from being sent. • Block email templates with impersonal greetings and reused content. • Hunt for consistent spelling mistakes across messages.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
EUROPE EUROPE financefinance logisticslogistics manufacturingmanufacturing technologytechnology
Intelligence Sources
Infosecurity-Magazine 2026-03-31