PhantomVAI is a .NET-based malware-as-a-service loader used to deliver follow-on malware, including XWorm. It is also tracked as VMDetectLoader and VMDetector Loader. The loader has been observed in multi-stage delivery chains associated with ClickFix-style social-engineering lures, where victims are induced to execute PowerShell that launches additional stages through LOLBin abuse. PhantomVAI is characterized by heavy .NET obfuscation, simple payload encoding schemes based on string reversal followed by base64 or hexadecimal decoding, anti-virtualization checks, persistence mechanisms, and process injection. Reported anti-analysis behavior includes detection of common virtualized environments such as VirtualBox, VMware, and VirtualPC. Persistence has been established through scheduled tasks and startup registry entries. Execution and defense evasion tradecraft includes abuse of mshta.exe in upstream delivery and RUNPE-style process hollowing into RegAsm.exe for payload execution. The loader has been described as being marketed as a delivery mechanism for commodity malware, including Katz Stealer, indicating a financially motivated malware-service ecosystem rather than a state-directed intrusion set. Known aliases include VMDetectLoader and VMDetector Loader. High-confidence reporting supports its role as a loader and post-exploitation enabler, but does not by itself establish a stable, distinct operator cluster behind every deployment.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.