{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/actors/phantom-stealer/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":["Phantom Stealer"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WinSCP"],"_cs_severities":["medium"],"_cs_tags":["credential-theft","infostealer","windows"],"_cs_type":"threat","_cs_vendors":["Martin Prikryl"],"content_html":"\u003cp\u003eThis brief details a detection for unauthorized access to WinSCP's security configuration files, a common target for information-stealing malware. WinSCP, a popular free SFTP, SCP, S3, FTP, and WebDAV client for Windows, stores sensitive SSH and FTP session credentials, including plain-text passwords and private key references, within a specific user profile directory: \u003ccode\u003e%APPDATA%\\Martin Prikryl\\WinSCP 2\\Configuration\\Security\u003c/code\u003e. Information-stealing malware families, such as Phantom Stealer and Stealerium, specifically target this directory to harvest stored credentials for exfiltration. This detection focuses on identifying any process other than the legitimate WinSCP executable attempting to read or access files within this sensitive configuration path. Such activity is highly anomalous during routine system operation and strongly indicates an attempted credential theft. Defenders should prioritize investigation into any process triggering this alert, including its origin, parent process, and network communications, to mitigate potential unauthorized access to remote systems.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003e\u003cstrong\u003eInitial Compromise\u003c/strong\u003e: A threat actor gains initial access to a victim's Windows endpoint through various means, such as spearphishing, exploiting a vulnerable service, or drive-by download.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eMalware Deployment\u003c/strong\u003e: The attacker deploys an information-stealing malware, such as Phantom Stealer or Stealerium, to the compromised system.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eCredential Harvesting Initialization\u003c/strong\u003e: The deployed info-stealer executes, beginning its reconnaissance phase for valuable credentials.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eTargeted File Access\u003c/strong\u003e: The info-stealer attempts to access files located within the \u003ccode\u003e%APPDATA%\\Martin Prikryl\\WinSCP 2\\Configuration\\Security\u003c/code\u003e directory, which is known to contain sensitive WinSCP credentials.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eCredential Exfiltration\u003c/strong\u003e: The info-stealer reads and parses the WinSCP configuration files, extracting stored SSH and FTP credentials, including passwords and private keys.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eData Transmission\u003c/strong\u003e: The harvested credentials are then encoded and exfiltrated to attacker-controlled command and control (C2) infrastructure over various network protocols.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eUnauthorized Access\u003c/strong\u003e: Threat actors use the stolen credentials to gain unauthorized access to remote systems (e.g., servers, cloud instances) where WinSCP was configured to connect, enabling further lateral movement and data theft.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this credential theft technique can lead to severe consequences. Attackers can leverage stolen SSH and FTP credentials to gain unauthorized access to critical systems, including production servers, cloud environments, and internal networks. This access can facilitate further lateral movement, data exfiltration of sensitive intellectual property or customer data, deployment of additional malware (e.g., ransomware), and disruption of business operations. The targeted nature of WinSCP credentials implies the attacker is seeking access to specific, often high-value, remote resources configured by the user.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eDeploy the Sigma rule\u003c/strong\u003e in this brief to your SIEM and tune for your environment.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eEnable Windows Security Event logging for EventCode 4663\u003c/strong\u003e (Object Access) on all endpoints to provide the necessary telemetry for this detection.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eInvestigate any alerts generated by this rule\u003c/strong\u003e by examining the \u003ccode\u003eprocess_name\u003c/code\u003e, \u003ccode\u003eprocess_path\u003c/code\u003e, and \u003ccode\u003eprocess_id\u003c/code\u003e fields, along with associated network connections.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eReview network logs and proxy logs\u003c/strong\u003e for connections from the identified suspicious process to external or unusual IP addresses, which may indicate credential exfiltration.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-27T18:29:21Z","date_published":"2026-07-27T18:29:21Z","id":"https://feed.craftedsignal.io/briefs/2026-07-winscp-credential-theft-detection/","summary":"This analytic detects unauthorized access to the WinSCP security configuration folder, which stores sensitive SSH and FTP credentials, by processes other than WinSCP, leveraging Windows Security Event 4663 to identify abnormal read or access attempts often indicative of credential-stealing malware like Phantom Stealer.","title":"Detection of Unauthorized WinSCP Credential Access","url":"https://feed.craftedsignal.io/briefs/2026-07-winscp-credential-theft-detection/"}],"language":"en","title":"CraftedSignal Threat Feed - Phantom Stealer","version":"https://jsonfeed.org/version/1.1"}