Digital Ghost: “PhantomVAI” Malware Revives Decade-Old RunPE Tricks
ID: e9c60997-8516-5c7c-b093-8f73fa0b75c8
STIX ID: report--e9c60997-8516-5c7c-b093-8f73fa0b75c8
Feed Name: securityonline.info
Threat Score
Intrinsec reports on PhantomVAI, a custom loader derived from an old RunPE utility used in worldwide campaigns to deliver infostealers and other payloads; it employs process hollowing and Windows Task Scheduler masquerading to evade detection, includes identifiable artifacts such as the namespace 'Hackforums.gigajew' and a component called Mandark (x64.load), and the report recommends enabling MFA and enhancing network monitoring to detect C2 activity and credential theft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
