HomeSecurityDEAD#VAX Campaign Deploys AsyncRAT via Phishing VHD Files

DEAD#VAX Campaign Deploys AsyncRAT via Phishing VHD Files

Threat researchers have revealed details of a new malware campaign dubbed DEAD#VAX, which uses a combination of disciplined engineering and clever abuse of legitimate system features to bypass traditional detection mechanisms and deploy a remote access Trojan (RAT) known as AsyncRAT.

See also: New cyber threats use QR codes, ClickFix and LOLBins

AsyncRAT
DEAD#VAX Campaign Deploys AsyncRAT via Phishing VHD Files

The attack exploits VHD files hosted on IPFS, extreme script obfuscation, decryption at runtime, and shell code injection into memory in trusted Windows processes, without ever leaving a decrypted binary on disk, according to Securonix, Shikha Sangwan , and Aaron Beardslee.

AsyncRAT is an open-source malware that gives attackers extensive control over compromised endpoints, allowing monitoring and data collection through keystroke logging, screen and camera capture, clipboard monitoring, file system access, remote command execution, and persistence across reboots.

The infection sequence begins with a phishing email that delivers a Virtual Hard Drive (VHD) hosted on the decentralized InterPlanetary Filesystem (IPFS). The VHD files are disguised as PDF purchase order files to deceive targets.

The multi-layered campaign uses Windows Script Files (WSF), heavily decrypted batch scripts, and self-parsing PowerShell loaders to deliver an encrypted x64 shellcode. The shellcode, AsyncRAT, is injected directly into trusted Windows processes and runs entirely in memory, minimizing any forensic evidence on disk.

See also: ScreenConnect used to distribute RATs

DEAD#VAX Campaign Deploys AsyncRAT via Phishing VHD Files
DEAD#VAX Campaign Deploys AsyncRAT via Phishing VHD Files

When a user opens the PDF-like file and double-clicks it, it mounts as a virtual hard drive. Using a VHD file is a specific and effective evasion technique used in modern malware campaigns, allowing it to bypass certain security checks.

is presented within the newly mounted drive “E:\” which, when executed by the victim, drops and executes a decrypted batch script. This script first checks whether it is not running within a virtualized or sandboxed environment and whether it has the necessary privileges to proceed.

Once all conditions are met, the script unleashes a PowerShell and persistence module designed to validate the execution environment, decrypt embedded payloads, configure persistence using scheduled tasks, and inject the final malware into Microsoft-signed Windows processes (e.g. RuntimeBroker.exe, OneDrive.exe, taskhostw.exe, and sihost.exe) to avoid writing evidence to disk.

The PowerShell component lays the foundation for a hidden, resilient execution engine that allows the trojan to run entirely in memory and integrate into legitimate system activity, allowing long-term access to compromised environments.

To enhance stealth, the malware controls execution timing and limits execution using sleep intervals to reduce CPU usage, avoid suspiciously fast Win32 API activity, and make execution behavior less abnormal.

See also: AsyncRAT exploits ConnectWise ScreenConnect

DEAD#VAX Campaign Deploys AsyncRAT via Phishing VHD Files
DEAD#VAX Campaign Deploys AsyncRAT via Phishing VHD Files

Modern malware campaigns increasingly rely on trusted file formats, script abuse, and in-memory execution to bypass traditional security controls. Instead of delivering a single malicious binary, attackers are constructing multi-layered execution pipelines in which each component appears harmless when analyzed in isolation. This shift has made detection, analysis, and incident response significantly more difficult for defenders.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS