PhantomVAI Loader is a C#/.NET malware loader tracked by Unit 42, previously referred to as Katz Stealer Loader and also known as VMDetectLoader. It has been distributed in phishing campaigns, including shipment-themed lures as well as sales, payment, and legal-action themes, using archived and obfuscated JavaScript or VBS attachments as the initial stage. These scripts execute Base64-encoded PowerShell that downloads image or GIF files containing a hidden Base64-encoded DLL payload via steganography, including samples where the payload was delimited by markers such as <<sudo_png>> and <<sudo_odt>>.
Once decoded and executed, PhantomVAI Loader performs anti-analysis checks focused on virtual machine detection using computer, BIOS, hard disk, PnP device, and Windows service information, and exits if it detects an analysis environment. The VM detection logic reportedly appears based on the GitHub VMDetector project. The loader establishes persistence through scheduled tasks that run PowerShell commands or wscript.exe, and can also use a Run registry key. It downloads a final payload from a command-line-supplied C2 URL and injects it into a target process using process hollowing, most commonly MSBuild.exe, including processes under Framework, Framework64, System32, or SysWOW64 paths.
Unit 42 initially observed PhantomVAI Loader delivering Katz Stealer, a malware-as-a-service infostealer advertised on BreachForums, exploit[.]in, and xss[.]is. Later campaigns used the loader to deploy additional malware families including AsyncRAT, XWorm, FormBook, and DCRat. Reported targeting was global and included organizations in manufacturing, education, utilities, technology, healthcare, information, and government sectors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
PhantomVAI Loader uses one or all of the following methods to create persistence: A scheduled task executes PowerShell commands to download a file from an attacker-controlled URL.
The script embeds a Base64-encoded PowerShell script and executes it to download and deliver the next stage of the infection.
PhantomVAI Loader uses one or all of the following methods to create persistence: A scheduled task executes PowerShell commands to download a file from an attacker-controlled URL.
Threat actors obfuscate these scripts in an attempt to bypass detections.
The PowerShell script downloads a GIF or other image file that conceals the loader payload. This technique is known as steganography.
It then injects this payload into a target process that is also defined by a command-line parameter, using the process hollowing technique.
44 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Related .NET loader used in phishing campaigns to deliver stealer payloads through a multi-stage chain involving obfuscated scripts, PowerShell, steganography, environment checks, persistence, and final payload injection via process hollowing.
Phishing-delivered loader used to deploy follow-on payloads including RATs and information stealers; originally used to deliver Katz Stealer.
A loader reported to use image steganography to inject a secondary payload (Katz Stealer) and evade sandbox analysis.
Malware loader distributed via phishing, delivers stealers and RATs, uses VM checks, persistence, and process hollowing.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.