Threat Advisory

PhantomRaven LLM-Generated Information Stealer Reads Arbitrary Files

Threat: Malware
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A financially motivated threat actor, who works as a bug bounty hunter, developed and distributed the JavaScript-based information stealer PhantomRaven via npm. The actor likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code, and statistical token-analysis patterns. The threat actor deployed PhantomRaven by contacting potential victim organizations and claiming to have identified compromised devices due to dependency-confusion attacks that used malicious npm packages.

The actor attributed the compromise to a dependency-confusion attack that used malicious npm packages to deploy PhantomRaven. They used remote dynamic dependency (RDD) links to the domain for command and control (C2). Infection occurred via email, where the threat actor contacted potential victims claiming to have identified compromised devices.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A financially motivated threat actor, who works as a bug bounty hunter, developed and distributed the JavaScript-based information stealer PhantomRaven via npm. The actor likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code, and statistical token-analysis patterns. The threat actor deployed PhantomRaven by contacting potential victim organizations and claiming to have identified compromised devices due to dependency-confusion attacks that used malicious npm packages.

The actor attributed the compromise to a dependency-confusion attack that used malicious npm packages to deploy PhantomRaven. They used remote dynamic dependency (RDD) links to the domain for command and control (C2). Infection occurred via email, where the threat actor contacted potential victims claiming to have identified compromised devices.[emaillocker id="1283"]

The threat actor has been active and has collected bounties from at least nine entities across various sectors. They operate under multiple usernames, including jpdhellonpm1 and jpd15, which are similar to industry sources associated with PhantomRaven deployments using malicious npm packages. The threat actor uses the information stealer solely to identify bug bounty opportunities.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1195 Supply Chain Compromise -
Initial access T1195.002 Supply Chain Compromise Compromise Software Supply Chain
Execution T1059.007 Command and Scripting Interpreter JavaScript
Persistence T1543.003 Create or Modify System Process Windows Service
Defence Evasion T1036.005 Masquerading Match Legitimate Resource Name or Location
Credential access T1552.001 Unsecured Credentials Credentials In Files
Discovery T1082 System Information Discovery -
Collection T1005 Data from Local System -
Command and control T1071.001 Application Layer Protocol Web Protocols
Exfiltration T1041 Exfiltration Over C2 Channel -

MBC MAPPING:

Objective Behavior ID Behavior
Discovery E1083 File and Directory Discovery
Discovery E1082 System Information Discovery
Command & Control B0030 C2 Communication
Impact B0022 Remote Access

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu