logo

DEAD#VAX Malware Campaign Deploys AsyncRAT via IPFS-Hosted VHD Phishing Files

ID: a6819f41-8457-5bd9-bb33-bbd735c52522

STIX ID: report--a6819f41-8457-5bd9-bb33-bbd735c52522

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-02-04

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

DEAD#VAX is a sophisticated, fileless malware campaign that uses IPFS-hosted VHD files masquerading as PDFs to deliver a multi-stage loader (obfuscated WSF, batch scripts, and PowerShell) which decrypts and injects AsyncRAT shellcode directly into trusted Microsoft-signed processes in memory. The chain includes sandbox/VM checks, runtime decryption, execution throttling to avoid detection, and scheduled-task persistence, minimizing disk artifacts and complicating detection and forensic response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.