Security researchers reported a widespread phishing-driven malware delivery operation using a custom loader dubbed PhantomVAI, which masquerades as legitimate software and uses process hollowing (RunPE) to inject payloads into legitimate Windows processes. The loader has been observed targeting users globally via malicious email attachments and links, then downloading and executing remote payloads in a way intended to blend into normal system activity and complicate detection.
Analysis attributed to Intrinsec links PhantomVAI’s core execution to a legacy, open-sourced RunPE utility (“Mandark”) originally shared on hacking forums (including code fingerprints such as Hackforums.gigajew). Researchers also noted Windows Task Scheduler masquerading (e.g., appearing as Microsoft.Win32.TaskScheduler.dll based on a legitimate GitHub project) and shared code traits (e.g., a “VAI” method and Portuguese strings). Multiple vendors reportedly tracked the same loader under different names (e.g., VMDetectLoader and Caminho Loader), and it has been associated with delivering commodity malware families including Remcos, XWorm, AsyncRAT, DarkCloud, and SmokeLoader.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
Alongside its technical findings, Intrinsec recommended mitigations including enabling MFA for browser-related accounts and improving network monitoring for suspicious outbound command-and-control traffic. The guidance was aimed at reducing the impact of the infostealers commonly delivered by PhantomVAI campaigns.
Intrinsec reported that PhantomVAI was built by repurposing a decade-old RunPE utility and tied its lineage to the older Mandark tool through shared code traits and the "Hackforums.gigajew" namespace. The firm also documented the loader's use of process hollowing, Windows Task Scheduler masquerading, and a core component named Mandark (x64.load) in the infection chain.
Security organizations observed the same malware loader but referred to it by different names, including PhantomVAI, VMDetectLoader, and Caminho Loader. This created confusion around attribution and the loader's capabilities across reporting.
Threat actors deployed the custom Windows loader PhantomVAI in widespread worldwide campaigns, using phishing to infect victims and deliver infostealers and remote access trojans. The loader accepted arbitrary payload URLs and was assessed as potentially operating as a loader-as-a-service.
An open-source RunPE utility later referred to as Mandark was originally published by a HackForums user. Researchers later identified the namespace "Hackforums.gigajew" as a code fingerprint linking newer malware to this older tool.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.