Operation MoneyMount-ISO: Phantom Stealer Deployment via ISO episode artwork

EPISODE · Dec 16, 2025 · 37 MIN

Operation MoneyMount-ISO: Phantom Stealer Deployment via ISO

from Decoded: The Cybersecurity Podcast · host Edward Henriquez

"Operation MoneyMount-ISO," an active cyber campaign originating from Russia that targets finance, accounting, and other related sectors through a sophisticated phishing scheme. The attack begins with a fake bank transfer confirmation email, written in formal Russian, which contains a malicious ZIP file leading to an ISO-mounted executable. This multi-stage infection ultimately deploys the Phantom Stealer malware, a potent information-stealing payload. Seqrite Labs’ research explains the malware’s capabilities, including extensive anti-analysis features, credential harvesting from browsers and crypto wallets, keylogging, clipboard monitoring, and data exfiltration via platforms like Telegram, Discord, and FTP. The operation is noted for its use of ISO mounting to bypass traditional email security controls, reflecting an increasing trend toward more complex initial access techniques for financially motivated cybercrime.

Episode metadata supplied by the publisher feed · Published Dec 16, 2025

Embed this episode

NOW PLAYING

Operation MoneyMount-ISO: Phantom Stealer Deployment via ISO

0:00 37:12

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Decoded: The Cybersecurity Podcast?

This episode is 37 minutes long.

When was this Decoded: The Cybersecurity Podcast episode published?

This episode was published on December 16, 2025.

Can I download this Decoded: The Cybersecurity Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!