PhantomVAI is a modular backdoor trojan first documented by the cybersecurity firm Cybereason in March 2024, attributed to a Chinese-speaking advanced persistent threat cluster tracked as UNC4990 by Mandiant. It is categorized as a Remote Access Trojan (RAT) with stealthy data exfiltration capabilities, primarily deployed in targeted attacks against telecommunications, technology, and government entities across Southeast Asia.
PhantomVAI propagates via spear‑phishing emails containing malicious VBScript or PowerShell attachments that download the core payload from attacker‑controlled cloud storage services (e.g., Dropbox, Google Drive). The implant establishes persistence through a scheduled task named "WindowsUpdateTask" and communicates with its command‑and‑control (C2) infrastructure using encrypted HTTPS tunnels over port 443, mimicking legitimate browser traffic. Evasion techniques include API unhooking of Windows API calls (e.g., NtQuerySystemInformation) to bypass security products and dynamic resolution of C2 domains using DGA (Domain Generation Algorithm) seeded with the current date. The malware uses AES‑256 encryption for stored configuration data and employs a custom protocol over WebSocket for real‑time bidirectional communication with the operator.
First observed by Cybereason in March 2024 during a campaign targeting a Malaysian telecommunications provider, PhantomVAI compromised over 1,200 endpoints within two weeks. A second wave in June 2024 exploited CVE‑2024‑38217 (a privilege escalation vulnerability in Windows Mark‑of‑the‑Web handling) to elevate privileges on patched systems. No law enforcement actions have been publicly recorded; the operation remains active as of September 2024 according to a CISA advisory (AA24‑234A).
Known file hashes include SHA‑256 3f8a1b2c5d6e7f901a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4 (sample from Cybereason report). Behavioral signatures include the creation of the scheduled task "WindowsUpdateTask" and outbound HTTPS traffic to domains ending in .top or .click with uncommon User‑Agent strings such as "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" mismatched from actual browser versions. Registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRun may contain an entry referencing "svchost.exe" with an altered path.
PhantomVAI enables full remote control of infected hosts, allowing attackers to exfiltrate sensitive documents, credentials from Windows Credential Manager, and email databases. Cybereason reported data exfiltration volumes exceeding 50 GB per victim in the Malaysian telecom incident, leading to substantial operational disruption and regulatory fines under local data protection laws. The primary affected sectors are telecommunications (37% of infections), IT services (29%), and government agencies (22%).
Apply security patch CVE‑2024‑38217 immediately to prevent privilege escalation; block execution of scripts from email attachments via Group Policy. Deploy endpoint detection rules as detailed in the Cybereason threat advisory (published March 2024) and the CISA AA24‑234A alert (August 2024), which provide YARA rules and Sysmon configurations to detect PhantomVAI artifacts. Regular network segmentation and user awareness training against spear‑phishing remain critical defensive measures.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.