Mandark is a RunPE/process-hollowing utility identified as a core component in the infection chain of the PhantomVAI Windows malware loader, including a component referenced as x64.load. According to the provided reporting, Mandark was originally developed by the HackForums user "gigajew" and open-sourced several years ago; the namespace "hackforums.gigajew" was observed in related code, linking the lineage to that older tool. In the observed campaigns, Mandark is responsible for preparing the victim environment and executing the final payload. Its behavior includes creating a suspended legitimate Windows process, unmapping its memory, allocating memory with read/write/execute permissions, copying PE headers and sections from a downloaded payload into the target process, patching processor registers to support import resolution and relocation, and resuming the suspended thread to run the injected payload. In the broader PhantomVAI activity, this capability was used in worldwide phishing campaigns to deliver malware families including Remcos, XWorm, AsyncRAT, DarkCloud, and SmokeLoader, often while masquerading as the legitimate Microsoft.Win32.TaskScheduler.dll version 2.11.0.0 to hinder detection. High-confidence indicators and traits mentioned in the content include the strings/namespace "hackforums.gigajew," the component name x64.load, and association with Windows Task Scheduler masquerading in PhantomVAI-related infections.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Open-sourced RunPE/process-hollowing utility leveraged by PhantomVAI to create a suspended process, unmap memory, and inject/execute a PE payload.
Component in the PhantomVAI infection chain responsible for environment preparation and execution of the final payload.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.