Close Menu
Alpha Leaders
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
What's On
What is red light therapy? Benefits, uses, and more

What is red light therapy? Benefits, uses, and more

21 May 2026
How Instagram Became A Venture Capital Deal Engine

How Instagram Became A Venture Capital Deal Engine

21 May 2026
British government’s answer to cost-of-living crisis: discounts on theme park tickets, chocolate bars

British government’s answer to cost-of-living crisis: discounts on theme park tickets, chocolate bars

21 May 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Alpha Leaders
newsletter
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
Alpha Leaders
Home » New 10-Second Phantom Goblin Infostealer Bypasses Browser Security
Innovation

New 10-Second Phantom Goblin Infostealer Bypasses Browser Security

Press RoomBy Press Room10 March 20253 Mins Read
Facebook Twitter Copy Link Pinterest LinkedIn Tumblr Email WhatsApp
New 10-Second Phantom Goblin Infostealer Bypasses Browser Security

The infostealer threat continues apace with everything from fake CAPTCHA tests and even Mac computers being used to steal data that has resulted in small business access being available for $600 on the dark web, and hundreds of millions of compromised passwords put up for sale. Now security researchers have uncovered a new threat in the infostealer armory, the Phantom Goblin that can glide around browser security protections. Here’s what you need to know.

The Phantom Goblin Infostealer Threat Unmasked

Although there is a lot that is very familiar when it comes to the newly discovered Phantom Goblin infostealer campaign, putting these recognisable attack components together in the way they have been, threat actors have come up with a very dangerous concoction that can bypass browser protections to steal credentials and cookies.

So, while there’s nothing particularly shocking about the use of social engineering or phishing tactics to persuade a victim to execute a malicious file disguised as a PDF document, or leveraging PowerShell to download and execute commands, or even establish VSCode tunnels and maintain ongoing access to exfiltrate sensitive information by way of a Telegram bot, ignoring the latest discovery would be a stupid thing to do when there is so much at stake.

Researchers at Cyble said that the Phantom Goblin campaign is distributing its infostealer malware through attachments compressed using the proprietary RAR format, and then tricking users into executing a malicious file using the Windows LNK shortcut and disguised as a legitimate PDF document. “Once executed,” Cyble said, “this LNK file triggers a PowerShell command that retrieves additional payloads from a GitHub repository, allowing the malware to perform various malicious activities while operating stealthily.” Interestingly, a number of 10-second delays are built into the attack process, before the PowerShell script launches a “code.exe” execution iin a hidden window and then again before reading the contents of the output.txt file.

Infostealer Bypasses Browser Security Protections

According to the Cyble report, Phantom Goblin will forcefully terminate browser processes and leverages Visual Studio Code tunnels to enable the attackers to control now compromised systems without triggering security alerts. “By disguising itself as legitimate applications,” the researchers explained, “the malware effectively bypasses detection while exfiltrating stolen data through a Telegram bot.”

As part of this security protections evading process, Phantom Goblin exploits legitimate and trusted tools including PowerShell and GitHub to blend “its activities into normal system operations,” and extract data that includes login credentials, cookies and browsing history. That exfiltrated data is first archived into compressed files making it harder for traditional security solutions to detect and block the infostealer attack.

Cyble researchers recommended that to mitigate the Phantom Goblin infostealer, you should avoid opening unexpected RAR, ZIP, or LNK files, even if they appear to come from trusted contacts, without verifying the source. Users are also advised to enable advanced email filtering to block potentially malicious attachments and ensure all attachments are scanned with updated security solutions before execution. Implementing strict browser security policies and access controls to prevent unauthorized debugging is also recommended where possible, alongside the restricted use of PowerShell and script execution on end-user systems.

Browser Attack Browser Credentials Browser Passwords Cyble Infosec Infostealer Attack Password compromise Passwords Passwords hack Phantom Goblin
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link

Related Articles

How Instagram Became A Venture Capital Deal Engine

How Instagram Became A Venture Capital Deal Engine

21 May 2026
Friday, May 22 Clues And Answers (#1,076)

Friday, May 22 Clues And Answers (#1,076)

21 May 2026
A Quarter Of College Students Using AI Daily Cheat With It

A Quarter Of College Students Using AI Daily Cheat With It

21 May 2026
Fidelity Collective Buys Up Westone Audio And Etymotic Brands

Fidelity Collective Buys Up Westone Audio And Etymotic Brands

21 May 2026
Securing The Internet’s Humanity

Securing The Internet’s Humanity

21 May 2026
Microsoft Is Scrapping SMS 2FA Codes—What You Need To Do

Microsoft Is Scrapping SMS 2FA Codes—What You Need To Do

21 May 2026
Don't Miss
Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

By Press Room27 December 2024

Every year, millions of people unwrap Christmas gifts that they do not love, need, or…

Exclusive: DeFi platform Azura launches after raising .9 million from Initialized

Exclusive: DeFi platform Azura launches after raising $6.9 million from Initialized

22 October 2024
Walmart dominated, while Target spiraled: the winners and losers of retail in 2024

Walmart dominated, while Target spiraled: the winners and losers of retail in 2024

30 December 2024
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Latest Articles
Anthropic lands in London as AI-powered coding—and the anxieties around it—go mainstream

Anthropic lands in London as AI-powered coding—and the anxieties around it—go mainstream

21 May 20261 Views
A Quarter Of College Students Using AI Daily Cheat With It

A Quarter Of College Students Using AI Daily Cheat With It

21 May 20263 Views
Intuit CFO on why the company is simplifying its structure

Intuit CFO on why the company is simplifying its structure

21 May 20261 Views
Fidelity Collective Buys Up Westone Audio And Etymotic Brands

Fidelity Collective Buys Up Westone Audio And Etymotic Brands

21 May 20262 Views

Recent Posts

  • What is red light therapy? Benefits, uses, and more
  • How Instagram Became A Venture Capital Deal Engine
  • British government’s answer to cost-of-living crisis: discounts on theme park tickets, chocolate bars
  • Friday, May 22 Clues And Answers (#1,076)
  • Anthropic lands in London as AI-powered coding—and the anxieties around it—go mainstream

Recent Comments

No comments to show.
About Us
About Us

Alpha Leaders is your one-stop website for the latest Entrepreneurs and Leaders news and updates, follow us now to get the news that matters to you.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks
What is red light therapy? Benefits, uses, and more

What is red light therapy? Benefits, uses, and more

21 May 2026
How Instagram Became A Venture Capital Deal Engine

How Instagram Became A Venture Capital Deal Engine

21 May 2026
British government’s answer to cost-of-living crisis: discounts on theme park tickets, chocolate bars

British government’s answer to cost-of-living crisis: discounts on theme park tickets, chocolate bars

21 May 2026
Most Popular
Friday, May 22 Clues And Answers (#1,076)

Friday, May 22 Clues And Answers (#1,076)

21 May 20262 Views
Anthropic lands in London as AI-powered coding—and the anxieties around it—go mainstream

Anthropic lands in London as AI-powered coding—and the anxieties around it—go mainstream

21 May 20261 Views
A Quarter Of College Students Using AI Daily Cheat With It

A Quarter Of College Students Using AI Daily Cheat With It

21 May 20263 Views

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • March 2022
  • January 2021
  • March 2020
  • January 2020

Categories

  • Blog
  • Business
  • Entrepreneurs
  • Global
  • Innovation
  • Leadership
  • Living
  • Money & Finance
  • News
  • Press Release
© 2026 Alpha Leaders. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.