Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

PhantomVAI Custom Loader Abuses RunPE Utility to Launch Stealthy Attacks on Users

## Cybersecurity: Analysis of PhantomVAI Loader

Cybersecurity: Analysis of PhantomVAI Loader

PhantomVAI is a new custom "loader" utilized in cyberattacks globally. A loader is a type of malicious software engineered to clandestinely download and execute other harmful programs on a victim’s computer. PhantomVAI is distinguished by its use of an older tool known as "RunPE".

This loader has been identified in various attack campaigns, deploying different types of malware aimed at information theft or computer control.

The core component of PhantomVAI is a utility called "Mandark", originally developed and shared on HackForums by a user named "gigajew". Mandark employs a technique known as "process hollowing", allowing malware to conceal itself within a legitimate program on Windows.

Using this old code, attackers have developed PhantomVAI to inject malicious payloads into trusted processes, making detection by security software more challenging as it appears as a normal program.

The loader is named "PhantomVAI" due to its unique method called "VAI" and its stealthy operation.

PhantomVAI is a new custom "loader" utilized in cyberattacks globally.
Anna Fields · Thehackingpost

Worldwide Deployment and Loader-as-a-Service

PhantomVAI is reportedly being offered as a service, referred to as "Loader-as-a-Service". This model allows various cybercriminals to pay for the use of PhantomVAI to distribute their malware.

It has been utilized to deploy several harmful threats, including:

Remcos and AsyncRAT: Remote access tools enabling control over a victim's computer. XWorm and DarkCloud: Malware designed to exfiltrate data. SmokeLoader and Lokibot: Programs that download additional malware or extract passwords.

These attacks are conducted globally, often using phishing emails to deceive targets into downloading the loader.

Advertisement

To evade detection, PhantomVAI often masquerades as legitimate software, such as Microsoft.Win32.TaskScheduler.dll, a genuine developer tool. It also impersonates popular software like AnyDesk.

Interestingly, the code of PhantomVAI contains several Portuguese words, suggesting that the developer might be from Portugal or Brazil. The loader features a "VMDetector" to identify if it is running in a test environment, ceasing operation to prevent analysis.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories