logo

Digital Ghost: “PhantomVAI” Malware Revives Decade-Old RunPE Tricks

ID: e9c60997-8516-5c7c-b093-8f73fa0b75c8

STIX ID: report--e9c60997-8516-5c7c-b093-8f73fa0b75c8

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-02-04

Date Updated: 2026-04-23

Author: Ddos

...
...

Intrinsec reports on PhantomVAI, a custom loader derived from an old RunPE utility used in worldwide campaigns to deliver infostealers and other payloads; it employs process hollowing and Windows Task Scheduler masquerading to evade detection, includes identifiable artifacts such as the namespace 'Hackforums.gigajew' and a component called Mandark (x64.load), and the report recommends enabling MFA and enhancing network monitoring to detect C2 activity and credential theft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.