Security analysts have identified an ongoing, targeted intrusion campaign—designated Operation MoneyMount-ISO1—actively targeting Russian enterprises, with a pronounced focus on financial, banking-adjacent, and accounting functions. The operation demonstrates deliberate victim profiling and controlled malware delivery consistent with financially motivated intrusion activity.

Attack Chain and Delivery Methodology

The campaign relies on highly tailored spear-phishing emails crafted to resemble time-sensitive financial communications, most commonly requests to verify or approve bank transfer transactions. Attached to these emails is a compressed ZIP archive containing a malicious ISO disk image (e.g., “Bank transfer confirmation.iso”).

When the ISO file is opened, it is mounted by the operating system as a virtual optical drive. The mounted image includes a malicious dynamic-link library (DLL) that is executed via native Windows mechanisms, enabling execution without reliance on macros or overt exploit code. This technique increases the likelihood of bypassing email gateway filtering and user suspicion, while leveraging trusted OS functionality to initiate payload execution.

The DLL ultimately deploys Phantom Stealer2, a credential-harvesting malware family designed for broad data collection and rapid monetization.

Phantom Stealer Functional Profile

Phantom Stealer operates as a multi-vector information stealer with capabilities that include:

  • Harvesting credentials and sensitive data from cryptocurrency wallet browser extensions and locally installed wallet applications
  • Extracting browser-resident artifacts such as saved credentials, session cookies, stored payment card data, and authentication tokens (including Discord tokens)
  • Capturing arbitrary files of interest, monitoring clipboard contents, and performing keystroke logging to collect credentials not stored on disk
  • Conducting host environment reconnaissance to detect virtual machines, debuggers, or sandbox indicators, enabling execution flow adjustments to evade automated analysis
  • Exfiltrating collected data using multiple covert channels, including Telegram bot APIs, Discord webhooks, and direct FTP connections, allowing flexible C2 infrastructure usage

Related and Parallel Threat Activity

Operation MoneyMount-ISO aligns with a broader increase in targeted cyber operations against Russian organizations across multiple verticals:

  • Adjacent Campaigns: A separate phishing operation attributed to threat cluster UNG09023—referred to by researchers as DupeHike—uses lures related to bonuses and internal financial policies to deploy an undocumented loader named DUPERUNNER. This loader subsequently installs the open-source AdaptixC24 framework.
  • Additional Activity: Concurrent phishing campaigns have targeted legal and aerospace entities, delivering well-known offensive tooling and commodity malware such as Cobalt Strike5, Formbook, DarkWatchman, and PhantomRemote. In multiple cases, attackers leveraged previously compromised corporate email infrastructure to propagate phishing messages, increasing credibility and delivery success rates.
  • Attribution Observations: Activity observed between June and September 2025 targeting the Russian aerospace sector has been partially attributed to hacktivist-aligned operators with pro-Ukrainian affiliations. Researchers have noted tooling and infrastructure overlaps with groups such as Hive0117 and Rainbow Hyena. These operations frequently utilized phishing pages hosted on decentralized or developer-friendly platforms (e.g., IPFS and Vercel) to harvest credentials for enterprise services, including Microsoft Outlook.

Assessment

Operation MoneyMount-ISO reflects a continued evolution toward precision phishing and file-format abuse in financially motivated intrusion campaigns. By combining social engineering, ISO-based payload delivery, and a feature-rich stealer such as Phantom Stealer, the operators demonstrate an effective tradecraft optimized for credential theft, financial fraud, and secondary access operations within high-value economic sectors.

Operation MoneyMount-ISO1 is a cybercrime campaign identified as a malware distribution operation. It primarily targets financial institutions and corporate users through malicious ISO disk image attachments. The campaign is notable for its multi-stage infection chain and focus on credential theft and remote access.

Phantom Stealer2 is a type of malicious software (malware) designed to extract sensitive data from infected computers. It typically targets stored credentials, browser data, cryptocurrency wallets, and system information for sale or misuse by cybercriminals. The malware is part of a broader category of “stealers” used in credential theft campaigns and dark-web marketplaces.

UNG09023 (also known as UNC0902) is a threat group tracked by cybersecurity researchers for conducting targeted espionage and cyber operations. The group is associated with sophisticated intrusion campaigns and has been linked to cyber activities of strategic interest, often attributed to state-sponsored motivations.

AdaptixC24 is a command-and-control (C2) framework used in cybersecurity operations and adversary emulation. Designed for red teams and penetration testers, it facilitates remote management of compromised hosts in controlled engagements. Its modular architecture and automation capabilities make it suitable for simulating advanced threat actor behaviors while maintaining operational security.

Cobalt Strike5 is a commercial penetration testing and red-team toolkit designed to simulate advanced cyberattacks. Although created for legitimate security assessments, its powerful post-exploitation and command-and-control (C2) features have made it a favored tool among threat actors for real-world intrusions and malware campaigns.