Quick Summary
The Securityish Brief
What Happened in the DEAD#VAX Campaign
The DEAD#VAX malware campaign was disclosed by threat hunters on February 4, 2026. It utilizes a combination of phishing tactics and advanced malware techniques to deploy AsyncRAT, a remote access trojan that allows attackers extensive control over compromised systems. The attack begins with phishing emails that deliver VHD files hosted on the InterPlanetary Filesystem (IPFS), disguised as PDF documents related to purchase orders.
This multi-stage attack leverages Windows Script Files (WSF), heavily obfuscated batch scripts, and PowerShell loaders to deliver encrypted shellcode. The AsyncRAT payload is injected directly into trusted Windows processes, allowing it to run entirely in memory and evade detection.
Implications for Cybersecurity
The use of VHD files as a delivery mechanism is particularly concerning, as it allows the malware to bypass certain security controls. When a user opens the seemingly benign PDF file, it mounts as a virtual hard drive, executing scripts that perform checks to ensure the environment is suitable for the attack.
Once the conditions are met, the malware injects itself into processes like RuntimeBroker.exe and OneDrive.exe, minimizing its footprint and making detection difficult. This fileless execution model highlights a shift in malware tactics, where attackers construct multi-stage pipelines that appear benign when analyzed individually.
Organizations and users must be vigilant, as this campaign exemplifies how modern malware increasingly relies on trusted file formats and script abuse to bypass security measures. The stealthy nature of this attack makes it challenging for traditional endpoint security solutions to detect and respond effectively.
As cyber threats evolve, understanding the techniques used in campaigns like DEAD#VAX is crucial for improving defenses and ensuring long-term security.
- AsyncRAT: An open-source malware that provides extensive control over compromised endpoints, enabling surveillance and data collection.
- VHD files: Virtual Hard Disk files that can be used to deliver malware while bypassing security controls.
- WSF: Windows Script Files that can execute scripts to facilitate malware deployment.
- PowerShell: A scripting language used to automate tasks and manage systems, which can also be exploited by malware.
- In-memory execution: A technique where malware runs directly in memory without leaving traces on disk, making it harder to detect.
Key Takeaways
- Be cautious of unexpected emails containing attachments, especially those claiming to be invoices or purchase orders.
- Ensure your antivirus and endpoint protection software are up to date to help detect advanced threats.
- Regularly monitor system processes for any unusual activity, particularly those related to trusted applications.
- Educate employees about phishing tactics and the importance of verifying the source of unexpected files.
- Implement strict access controls and permissions to limit the execution of potentially harmful scripts.
Key Terms & Concepts
- AsyncRAT: In this article, AsyncRAT refers to a remote access trojan that allows attackers to control compromised systems.
- VHD files: VHD files are Virtual Hard Disk files that can be used to deliver malware while appearing benign.
- WSF: WSF stands for Windows Script Files, which can execute scripts to facilitate malware deployment.
- PowerShell: PowerShell is a scripting language used for task automation and configuration management that can be exploited by malware.
- In-memory execution: In-memory execution is a technique where malware runs directly in memory without leaving traces on disk.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.