ThreatCluster

PhantomVAI Loader Exploits RunPE Utility in Global Phishing Campaigns

First seen 4 Feb 2026, 22:55 UTC GbhackersCybersecuritynews 39

Article Content

Browse articles
ThreatCluster

The PhantomVAI custom loader has been identified in phishing campaigns, delivering stealers and remote access trojans (RATs) to compromised systems. This malware disguises itself as legitimate software and utilizes process hollowing techniques to inject malicious payloads into Windows processes. Multiple security researchers have documented this threat across various organizations.