logo

PhantomVAI Custom Loader Abuses RunPE Utility to Launch Stealthy Attacks on Users

ID: dad2d191-c470-5c49-90ab-836df49292c0

STIX ID: report--dad2d191-c470-5c49-90ab-836df49292c0

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-02-04

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

PhantomVAI is a custom Windows loader derived from the public Mandark/RunPE utility that uses process hollowing to inject downloaded payloads; it is being offered as a Loader-as-a-Service and has been observed in global phishing campaigns distributing RATs and information-stealing malware while employing stealth techniques (VM detection and masquerading as legitimate DLLs).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.