PhantomVAI Custom Loader Abuses RunPE Utility to Launch Stealthy Attacks on Users
## Cybersecurity: Analysis of PhantomVAI Loader
Cybersecurity: Analysis of PhantomVAI Loader
PhantomVAI is a new custom "loader" utilized in cyberattacks globally. A loader is a type of malicious software engineered to clandestinely download and execute other harmful programs on a victim’s computer. PhantomVAI is distinguished by its use of an older tool known as "RunPE".
This loader has been identified in various attack campaigns, deploying different types of malware aimed at information theft or computer control.
The core component of PhantomVAI is a utility called "Mandark", originally developed and shared on HackForums by a user named "gigajew". Mandark employs a technique known as "process hollowing", allowing malware to conceal itself within a legitimate program on Windows.
Using this old code, attackers have developed PhantomVAI to inject malicious payloads into trusted processes, making detection by security software more challenging as it appears as a normal program.
The loader is named "PhantomVAI" due to its unique method called "VAI" and its stealthy operation.
PhantomVAI is a new custom "loader" utilized in cyberattacks globally.
Worldwide Deployment and Loader-as-a-Service
PhantomVAI is reportedly being offered as a service, referred to as "Loader-as-a-Service". This model allows various cybercriminals to pay for the use of PhantomVAI to distribute their malware.
It has been utilized to deploy several harmful threats, including:
Remcos and AsyncRAT: Remote access tools enabling control over a victim's computer. XWorm and DarkCloud: Malware designed to exfiltrate data. SmokeLoader and Lokibot: Programs that download additional malware or extract passwords.
These attacks are conducted globally, often using phishing emails to deceive targets into downloading the loader.
To evade detection, PhantomVAI often masquerades as legitimate software, such as Microsoft.Win32.TaskScheduler.dll, a genuine developer tool. It also impersonates popular software like AnyDesk.
Interestingly, the code of PhantomVAI contains several Portuguese words, suggesting that the developer might be from Portugal or Brazil. The loader features a "VMDetector" to identify if it is running in a test environment, ceasing operation to prevent analysis.
Based on reporting by GBHackers.
