PhantomVAI Loader Launches Global Campaign to Distribute AsyncRAT, XWorm, FormBook, and DCRat
The PhantomVAI Loader, a .NET loader tracked by Unit 42, is utilized in global phishing campaigns to distribute various information-stealing malware. Originally identified as Katz Stealer Loader, it now supports AsyncRAT, XWorm, FormBook, and DCRat…
The PhantomVAI Loader, a .NET loader tracked by Unit 42, is utilized in global phishing campaigns to distribute various information-stealing malware. Originally identified as Katz Stealer Loader, it now supports AsyncRAT, XWorm, FormBook, and DCRat payloads through an infection chain that employs obfuscated scripts, steganography, and virtual-machine detection.
This loader targets sectors such as manufacturing, education, utilities, technology, healthcare, information, and government. The loader first emerged on April 13, 2025, as a malware-as-a-service offering known as Katz Stealer, designed to harvest sensitive data like credentials, browser information, cryptocurrency wallets, and communication logs.
The attack chain begins with a phishing operation and culminates in payload deployment. Researchers have rebranded it as PhantomVAI Loader to reflect its stealthy execution method and evolving payload capabilities. It is available on underground marketplaces, allowing attackers of varying skill levels to execute complex attacks.
Inside the Stealthy Multi-Stage Attack
The PhantomVAI infection chain unfolds in three stages:
Emails with themes of sales, payments, or legal actions are crafted, sometimes using homograph attacks to trick recipients into opening attachments. These ZIP archives contain obfuscated JavaScript or VBS files embedding a Base64-encoded PowerShell script, initiating the next stage download upon execution.
The PhantomVAI Loader, a .NET loader tracked by Unit 42, is utilized in global phishing campaigns to distribute various information-stealing malware.
Steganographic PowerShell Stage
The decoded PowerShell script retrieves a seemingly innocuous image from a command-and-control server. Steganography hides text within the image, encoding a Base64 DLL payload, which is extracted, decoded, and loaded by the script.
PhantomVAI Loader Execution
Written in C#, the loader checks for virtual-machine environments using VMDetector techniques. If operating in a sandbox, it aborts. Otherwise, it establishes persistence and downloads the final payload—such as AsyncRAT, XWorm, FormBook, or DCRat—and injects it into a legitimate executable like MSBuild.exe.
Palo Alto Networks offers proactive defenses against PhantomVAI Loader campaigns. The loader typically injects payloads into the Microsoft Build Engine executable, MSBuild.exe.
Advanced WildFire’s behavioral analysis detects obfuscated scripts and steganographic downloads, while Cortex XDR and XSIAM provide endpoint detection and incident response capabilities. Organizations should enforce strict email security policies, enable multi-factor authentication, maintain up-to-date endpoint protection, and conduct regular phishing awareness training.
If compromise is suspected, contact the Unit 42 Incident Response team for rapid containment and remediation. Understanding each phase of the PhantomVAI Loader attack chain is critical for thwarting these sophisticated threats and protecting sensitive data.
Based on reporting by GBHackers.
