Tag: VHD Phishing Files

DEAD#VAX Malware Campaign Deploys AsyncRAT via IPFS-Hosted VHD Phishing Files
News

DEAD#VAX Malware Campaign Deploys AsyncRAT via IPFS-Hosted VHD Phishing Files

Threat researchers have revealed information about a new, covert malware campaign called DEAD#VAX that uses a combination of "disciplined tradecraft and clever abuse of legitimate system features" to get past conventional detection methods and install the AsyncRAT remote access trojan (RAT). According to a report shared with The Hacker News by Securonix researchers Akshay Gaikwad, Shikha Sangwan, and Aaron Beardslee, the attack uses IPFS-hosted VHD files, extreme script obfuscation, runtime decryption, and in-memory shellcode injection into trusted Windows processes, never dropping a decrypted binary to disk. Through keylogging, screen and webcam capture, clipboard monitoring, file system access, remote command execution, and persistence between reboots, the open-source malware Asyn...