Close Menu
Alpha Leaders
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
What's On
Americans are woefully short on saving for retirement—Warren Buffett’s investing advice could help

Americans are woefully short on saving for retirement—Warren Buffett’s investing advice could help

5 March 2026
‘Usually everybody loves money’: Trump’s FDA chief to start giving bonuses for faster drug reviews

‘Usually everybody loves money’: Trump’s FDA chief to start giving bonuses for faster drug reviews

5 March 2026
Mark Zuckerberg, Adam Mosseri’s words used against them in never-before-seen videos airing in addiction trial

Mark Zuckerberg, Adam Mosseri’s words used against them in never-before-seen videos airing in addiction trial

5 March 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Alpha Leaders
newsletter
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
Alpha Leaders
Home » New 10-Second Phantom Goblin Infostealer Bypasses Browser Security
Innovation

New 10-Second Phantom Goblin Infostealer Bypasses Browser Security

Press RoomBy Press Room10 March 20253 Mins Read
Facebook Twitter Copy Link Pinterest LinkedIn Tumblr Email WhatsApp
New 10-Second Phantom Goblin Infostealer Bypasses Browser Security

The infostealer threat continues apace with everything from fake CAPTCHA tests and even Mac computers being used to steal data that has resulted in small business access being available for $600 on the dark web, and hundreds of millions of compromised passwords put up for sale. Now security researchers have uncovered a new threat in the infostealer armory, the Phantom Goblin that can glide around browser security protections. Here’s what you need to know.

The Phantom Goblin Infostealer Threat Unmasked

Although there is a lot that is very familiar when it comes to the newly discovered Phantom Goblin infostealer campaign, putting these recognisable attack components together in the way they have been, threat actors have come up with a very dangerous concoction that can bypass browser protections to steal credentials and cookies.

So, while there’s nothing particularly shocking about the use of social engineering or phishing tactics to persuade a victim to execute a malicious file disguised as a PDF document, or leveraging PowerShell to download and execute commands, or even establish VSCode tunnels and maintain ongoing access to exfiltrate sensitive information by way of a Telegram bot, ignoring the latest discovery would be a stupid thing to do when there is so much at stake.

Researchers at Cyble said that the Phantom Goblin campaign is distributing its infostealer malware through attachments compressed using the proprietary RAR format, and then tricking users into executing a malicious file using the Windows LNK shortcut and disguised as a legitimate PDF document. “Once executed,” Cyble said, “this LNK file triggers a PowerShell command that retrieves additional payloads from a GitHub repository, allowing the malware to perform various malicious activities while operating stealthily.” Interestingly, a number of 10-second delays are built into the attack process, before the PowerShell script launches a “code.exe” execution iin a hidden window and then again before reading the contents of the output.txt file.

Infostealer Bypasses Browser Security Protections

According to the Cyble report, Phantom Goblin will forcefully terminate browser processes and leverages Visual Studio Code tunnels to enable the attackers to control now compromised systems without triggering security alerts. “By disguising itself as legitimate applications,” the researchers explained, “the malware effectively bypasses detection while exfiltrating stolen data through a Telegram bot.”

As part of this security protections evading process, Phantom Goblin exploits legitimate and trusted tools including PowerShell and GitHub to blend “its activities into normal system operations,” and extract data that includes login credentials, cookies and browsing history. That exfiltrated data is first archived into compressed files making it harder for traditional security solutions to detect and block the infostealer attack.

Cyble researchers recommended that to mitigate the Phantom Goblin infostealer, you should avoid opening unexpected RAR, ZIP, or LNK files, even if they appear to come from trusted contacts, without verifying the source. Users are also advised to enable advanced email filtering to block potentially malicious attachments and ensure all attachments are scanned with updated security solutions before execution. Implementing strict browser security policies and access controls to prevent unauthorized debugging is also recommended where possible, alongside the restricted use of PowerShell and script execution on end-user systems.

Browser Attack Browser Credentials Browser Passwords Cyble Infosec Infostealer Attack Password compromise Passwords Passwords hack Phantom Goblin
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link

Related Articles

When Claude Paused: An AI Doomsday Preview And The Question Of Human Survival

3 March 2026

Data Plateau: Hit The Scaling Wall With AI Or Remain An Innovator?

3 March 2026
New Leak Signals Unprecedented Design Change

New Leak Signals Unprecedented Design Change

1 March 2026
Is Tourism A Tool Or A Threat?

Is Tourism A Tool Or A Threat?

1 March 2026
Trust In The AI Age

Trust In The AI Age

1 March 2026
LEGO Pikachu And Poke Ball (72152) Review: Lacking A Spark

LEGO Pikachu And Poke Ball (72152) Review: Lacking A Spark

1 March 2026
Don't Miss
Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

By Press Room27 December 2024

Every year, millions of people unwrap Christmas gifts that they do not love, need, or…

Walmart dominated, while Target spiraled: the winners and losers of retail in 2024

Walmart dominated, while Target spiraled: the winners and losers of retail in 2024

30 December 2024
Moltbook is the talk of Silicon Valley. But the furor is eerily reminiscent of a 2017 Facebook research experiment

Moltbook is the talk of Silicon Valley. But the furor is eerily reminiscent of a 2017 Facebook research experiment

6 February 2026
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Latest Articles
Fed rate cuts: Iran war and jobs data lower odds of 2026 interest cut

Fed rate cuts: Iran war and jobs data lower odds of 2026 interest cut

5 March 20260 Views
Pentagon commits 0M to a maritime tech VC fund, appears to be ramping up venture deals

Pentagon commits $150M to a maritime tech VC fund, appears to be ramping up venture deals

5 March 20260 Views
The housing paradox: why banning institutional investors could make affordability worse

The housing paradox: why banning institutional investors could make affordability worse

5 March 20261 Views
The Iran war is giving rise to a ‘mercantilism,’ a centuries-old economic theory

The Iran war is giving rise to a ‘mercantilism,’ a centuries-old economic theory

5 March 20261 Views
About Us
About Us

Alpha Leaders is your one-stop website for the latest Entrepreneurs and Leaders news and updates, follow us now to get the news that matters to you.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks
Americans are woefully short on saving for retirement—Warren Buffett’s investing advice could help

Americans are woefully short on saving for retirement—Warren Buffett’s investing advice could help

5 March 2026
‘Usually everybody loves money’: Trump’s FDA chief to start giving bonuses for faster drug reviews

‘Usually everybody loves money’: Trump’s FDA chief to start giving bonuses for faster drug reviews

5 March 2026
Mark Zuckerberg, Adam Mosseri’s words used against them in never-before-seen videos airing in addiction trial

Mark Zuckerberg, Adam Mosseri’s words used against them in never-before-seen videos airing in addiction trial

5 March 2026
Most Popular
Can Anthropic’s CFO sell Wall Street on an AI firm Washington calls a ‘risk’? 

Can Anthropic’s CFO sell Wall Street on an AI firm Washington calls a ‘risk’? 

5 March 20261 Views
Fed rate cuts: Iran war and jobs data lower odds of 2026 interest cut

Fed rate cuts: Iran war and jobs data lower odds of 2026 interest cut

5 March 20260 Views
Pentagon commits 0M to a maritime tech VC fund, appears to be ramping up venture deals

Pentagon commits $150M to a maritime tech VC fund, appears to be ramping up venture deals

5 March 20260 Views
© 2026 Alpha Leaders. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.