logo

Open the wrong “PDF” and attackers gain remote access to your PC

ID: db30e7d6-ae5b-59ae-8b3f-30ebe62ad815

STIX ID: report--db30e7d6-ae5b-59ae-8b3f-30ebe62ad815

Feed Name: Malwarebytes Blog

Threat Score
72/100

Date Published: 2026-02-05

Date Updated: 2026-04-28

...
...

DEAD#VAX is a phishing campaign that uses IPFS-hosted files masquerading as PDFs which are actually VHDs; when mounted they expose a WSF that executes and injects AsyncRAT shellcode into trusted, signed Windows processes to run entirely in memory, enabling credential theft, surveillance, and lateral movement. The report explains the infection chain, emphasizes stealthy in-memory execution and evasion techniques, and gives practical user guidance (show file extensions, verify attachments, use real-time anti-malware).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.