PhantomRaven: An LLM-Generated Information Stealer Developed for Bug Bounty Hunting
Cybersecurity Classified by Officially
CrowdStrike Counter Adversary Operations identified a financially motivated threat actor who works as a bug bounty hunter and who developed and distributed the JavaScript (JS)-based information stealer PhantomRaven via npm, a platform on which developers can access open-source packages to build applications and software. The developer likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code, and statistical token-analysis patterns.
In November 2025, the threat actor deploying PhantomRaven contacted a potential victim organization and claimed to have identified a compromised device. The threat actor attributed the compromise to a dependency-confusion attack that used malicious npm packages to deploy PhantomRaven. The email address used to contact the potential victim included the string JPD as part of the username.
The PhantomRaven operator is a self-proclaimed bug bounty hunter who has been active since November 2022. According to their public X profile, the threat actor has collected bounties from at least nine entities across the technology, retail, and hospitality sectors using reputable bug bounty submission platforms, including Bugcrowd, Intigriti, YesWeHack, HackenProof, and HackerOne. To date, CrowdStrike Counter Adversary Operations has not observed PhantomRaven logs for sale on log shops, further indicating that PhantomRaven’s operator likely uses the information stealer solely to identify bug bounty opportunities.
This is an extract. The publication continues at the source.
Read the original at the source: https://www.crowdstrike.com/en-us/blog/phantomraven-llm-generated-information-stealer-for-bug-bounty-hunting/
Officially imported this from CrowdStrike’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- CrowdStrike — imported from official source
- Official source
- https://www.crowdstrike.com/blog/feed/ RSS
- Imported
- September 18, 2026 11:35
- Versions
- 1 recorded
- Identity
https://www.crowdstrike.com/?p=781927