DEAD#VAX Malware Campaign Deploys AsyncRAT via IPFS-Hosted VHD Phishing Files
ID: a6819f41-8457-5bd9-bb33-bbd735c52522
STIX ID: report--a6819f41-8457-5bd9-bb33-bbd735c52522
Feed Name: The Hacker News
DEAD#VAX is a sophisticated, fileless malware campaign that uses IPFS-hosted VHD files masquerading as PDFs to deliver a multi-stage loader (obfuscated WSF, batch scripts, and PowerShell) which decrypts and injects AsyncRAT shellcode directly into trusted Microsoft-signed processes in memory. The chain includes sandbox/VM checks, runtime decryption, execution throttling to avoid detection, and scheduled-task persistence, minimizing disk artifacts and complicating detection and forensic response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
