Threat researchers have revealed information about a new, covert malware campaign called DEAD#VAX that uses a combination of “disciplined tradecraft and clever abuse of legitimate system features” to get past conventional detection methods and install the AsyncRAT remote access trojan (RAT).
According to a report shared with The Hacker News by Securonix researchers Akshay Gaikwad, Shikha Sangwan, and Aaron Beardslee, the attack uses IPFS-hosted VHD files, extreme script obfuscation, runtime decryption, and in-memory shellcode injection into trusted Windows processes, never dropping a decrypted binary to disk.
Through keylogging, screen and webcam capture, clipboard monitoring, file system access, remote command execution, and persistence between reboots, the open-source malware AsyncRAT gives attackers complete control over infiltrated endpoints, facilitating surveillance and data collecting.
A phishing email that delivers a Virtual Hard Disk (VHD) hosted on the decentralized InterPlanetary Filesystem (IPFS) network read more about DEAD#VAX Malware Campaign Deploys AsyncRAT via IPFS-Hosted VHD Phishing Files.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
