Operation PhantomCLR: Stealth Execution via AppDomain Hijacking and In-Memory .NET Abuse

Reported 18 Apr 2026 by otx · Severity: medium

A highly sophisticated multi-stage post-exploitation framework targeting organizations in the Middle East and EMEA financial sectors exploits legitimate digitally signed Intel utilities through .NET AppDomainManager mechanism abuse. The attack leverages trusted binary proxy execu