PhantomVAI Loader Exploits RunPE Utility in Global Phishing Campaigns
First seen 4 Feb 2026, 22:55 UTC
•
•39
Export
Article Content
Browse articles
The PhantomVAI custom loader has been identified in phishing campaigns, delivering stealers and remote access trojans (RATs) to compromised systems. This malware disguises itself as legitimate software and utilizes process hollowing techniques to inject malicious payloads into Windows processes. Multiple security researchers have documented this threat across various organizations.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Google Addresses Eighth Chrome Zero-Day Vulnerability in 2025
China-linked Cyber Group Expands Targeting to Southeastern Europe
China-Nexus APT UAT-7290 Targets South Asia Telecoms in Cyber Espionage Campaign
China-linked UAT-7290 Targets Telcos in Cyberespionage Campaign
UAT-7290 Cyber Espionage Targets South Asian Telecoms
APT28 Exploits MSHTML Zero-Day Vulnerability in Windows