logo

PhantomVAI Custom Loader Uses RunPE Utility to Attack Users

ID: dcdd72cb-9900-5f3f-8182-a1f75ba9834d

STIX ID: report--dcdd72cb-9900-5f3f-8182-a1f75ba9834d

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-02-04

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

PhantomVAI is a custom loader observed in worldwide phishing campaigns that masquerades as legitimate software and uses a RunPE/Mandark process-hollowing technique to inject remote payloads (notably Remcos, XWorm, AsyncRAT, DarkCloud, and SmokeLoader) into Windows processes; researchers identified shared markers across samples (a "VAI" method, Portuguese strings, and impersonation of Microsoft.Win32.TaskScheduler.dll) and report the loader is likely offered as a service, allowing multiple threat actors to deploy diverse malware and complicating detection and attribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.