DEAD#VAX Malware Campaign Deploys AsyncRAT via IPFS-Hosted VHD Phishing Files

Threat researchers have revealed information about a new, covert malware campaign called DEAD#VAX that uses a combination of “disciplined tradecraft and clever abuse of legitimate system features” to get past conventional detection methods and install the AsyncRAT remote access trojan (RAT).

According to a report shared with The Hacker News by Securonix researchers Akshay Gaikwad, Shikha Sangwan, and Aaron Beardslee, the attack uses IPFS-hosted VHD files, extreme script obfuscation, runtime decryption, and in-memory shellcode injection into trusted Windows processes, never dropping a decrypted binary to disk.

Through keylogging, screen and webcam capture, clipboard monitoring, file system access, remote command execution, and persistence between reboots, the open-source malware AsyncRAT gives attackers complete control over infiltrated endpoints, facilitating surveillance and data collecting.

A phishing email that delivers a Virtual Hard Disk (VHD) hosted on the decentralized InterPlanetary Filesystem (IPFS) network read more about DEAD#VAX Malware Campaign Deploys AsyncRAT via IPFS-Hosted VHD Phishing Files.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *