PhantomVAI Custom Loader Uses RunPE Utility to Attack Users
ID: dcdd72cb-9900-5f3f-8182-a1f75ba9834d
STIX ID: report--dcdd72cb-9900-5f3f-8182-a1f75ba9834d
Feed Name: cybersecurityNews.com
PhantomVAI is a custom loader observed in worldwide phishing campaigns that masquerades as legitimate software and uses a RunPE/Mandark process-hollowing technique to inject remote payloads (notably Remcos, XWorm, AsyncRAT, DarkCloud, and SmokeLoader) into Windows processes; researchers identified shared markers across samples (a "VAI" method, Portuguese strings, and impersonation of Microsoft.Win32.TaskScheduler.dll) and report the loader is likely offered as a service, allowing multiple threat actors to deploy diverse malware and complicating detection and attribution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
