Threat reportPhishingTL-2026-0092

DEAD#VAX AsyncRAT Campaign — IPFS-Hosted VHD Phishing, 5-Stage Fileless Infection Chain, Mark-of-the-Web Bypass, Self-Parsing Batch Scripts, 4-Layer PowerShell Deobfuscation, In-Memory Shellcode Injection into Trusted Processes

highMONITORING

DEAD#VAX AsyncRAT Campaign (TL-2026-0092) is a high-severity phishing campaign, first published 2026-01-14. It has no confirmed attribution, maps to 44 MITRE ATT&CK techniques (T1027, T1033, T1036), and is covered by 9 detection rules and 26 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
44MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
26Indicators of compromise

Key facts for TL-2026-0092

Threat ID
TL-2026-0092
Severity
HIGH
Status
MONITORING
Category
PHISHING
First published
Last reviewed
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
Manufacturing, Supply Chain, Technology, Healthcare
Target regions
Global
Detection rules
9
Indicators of compromise
26

Malware and tooling in DEAD#VAX AsyncRAT Campaign

Malware and tooling: AsyncRAT

How DEAD#VAX AsyncRAT Campaign works

DEAD#VAX is a sophisticated multi-stage malware campaign tracked by Securonix Threat Research that delivers AsyncRAT via IPFS-hosted VHD phishing lures. The attack chain progresses through VHD mounting (bypassing Mark-of-the-Web), WSF script execution, heavily obfuscated batch scripts with self-parsing logic, fileless PowerShell loaders with 4-layer deobfuscation, and in-memory shellcode injection into trusted Microsoft-signed processes — never writing a decrypted payload to disk.

DEAD#VAX is a multi-stage, fileless malware campaign documented by Securonix Threat Research (researchers Akshay Gaikwad, Shikha Sangwan, Aaron Beardslee, published January 14, 2026, advisory published February 4, 2026). The campaign delivers AsyncRAT through an elaborate 5-stage infection chain designed to evade traditional security controls at every step.

**Stage 1 — Initial Access (Phishing + IPFS-hosted VHD):** The attack begins with spear-phishing emails impersonating Progressive Components (procoms.com), a legitimate tooling supplier. The actual sending domain is mingyitc.com (likely compromised). The email creates artificial urgency with a 2-day response deadline and includes a fake 'Virus scan completed' banner. The download link points to a VHD file hosted on IPFS via the w3s.link gateway (bafybeiaj6jw2xhbppgji757tn3hg5uu6splaa5gyydkwnzwprzakcp44ve.ipfs.w3s.link). IPFS content-addressed hosting makes traditional URL-based takedowns ineffective — the file persists as long as any IPFS node pins it. At time of analysis, the phishing emails scored 0/0 on VirusTotal.

**Stage 2 — VHD Mount + MotW Bypass:** When the user double-clicks the downloaded VHD file, Windows 10/11 natively mounts it as a new logical drive. Files inside the VHD do NOT inherit the Mark-of-the-Web (MotW) from the container, appearing as local files on a local disk. The mounted drive contains a WSF script with a double extension (purchaseorder...pdf.wsf) designed to trick users into thinking it's a PDF. SmartScreen does not scan files from mounted VHDs as aggressively.

**Stage 3 — WSF → Batch Script Execution:** The WSF file is heavily obfuscated with fragmented string variables. It uses Msxml2.DOMDocument.3.0 COM objects for Base64 decoding (avoiding standard functions) and a rolling XOR decryption with key '4qrttc9sl-sdnYziCVHb8g'. The decrypted output is a batch file written to %TEMP%\temp with a random alphanumeric filename (MXVT60Xx6um7nRNl.bat).

**Stage 4 — Obfuscated Batch with Self-Parsing Logic:** The batch file uses environment variable explosion — thousands of SET commands with random variable names that map to individual characters/fragments. After deobfuscation, the batch performs: (1) Anti-analysis checks: admin privilege check via 'net session', VMware detection via WMI Win32_ComputerSystem/BIOS, RAM check (exits if <3GB — anti-sandbox), checks for analyst artifacts ('VBE', 'mapping.csv'). (2) Self-parsing: copies itself to rEgX.cmd, runs mbs.exe (renamed powershell.exe), reads its own content looking for lines starting with '@' to extract the hidden Base64 payload appended at the end. (3) Decryption: Base64 decode → rolling XOR with key 'md' → Invoke-Expression for in-memory execution. The decrypted code never touches disk.

**Stage 5 — Fileless PowerShell Loader + AsyncRAT Injection:** The final PowerShell stage is a sophisticated process injector with: (1) 4-layer string deobfuscation engine (fXZBcHpNzP): Unicode pollution removal → Base64 decode → rolling XOR → ROT character shift. (2) Native API access via Add-Type C# compilation: OpenProcess, VirtualAllocEx, WriteProcessMemory, CreateRemoteThread, ReadProcessMemory, VirtualQueryEx. (3) Target process enumeration: RuntimeBroker.exe, OneDrive.exe, taskhostw.exe, sihost.exe — all Microsoft-signed trusted processes. (4) Reinfection marker scanner: checks for byte sequence DEADBECAFEBAEF in target process memory to prevent duplicate injection. (5) Persistence: hidden scheduled task + VBS launcher with rotation logic (self-healing if artifacts removed, generates new randomized task names). (6) Payload stored at C:\ProgramData\IntelDriver\boot64x.w as noise-polluted Base64 data. (7) ~71KB x64 shellcode with entropy >7.7, no PE header — pure encrypted shellcode.

**AsyncRAT Final Payload:** Dynamic analysis confirmed the shellcode deploys a fully functional AsyncRAT implant with: keylogging, screen/webcam capture, clipboard monitoring, file system access, remote command execution, encrypted C2 (TCP/TLS), modular plugin architecture (StealerLib credential theft), and asynchronous command handling for long-running surveillance.

AsyncRAT (MITRE S1087) is an open-source C# RAT created by NYAN-x-CAT, available on GitHub under MIT license. It is widely abused by both low-skill actors and organized groups due to its modular design and extensive feature set. The DEAD#VAX campaign's sophistication (5-stage chain, fileless execution, 4-layer obfuscation, reinfection prevention, persistence rotation) suggests a more capable threat actor than typical AsyncRAT users.

MITRE ATT&CK techniques used in TL-2026-0092

defense-evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1036.003 Rename Legitimate Utilities; T1036.007 Double File Extension; T1055 Process Injection; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information; T1218.005 Mshta; T1497 Virtualization/Sandbox Evasion; T1497.001 System Checks; T1564 Hide Artifacts; T1564.003 Hidden Window; T1620 Reflective Code Loading; T1622 Debugger Evasion

discovery

T1033 System Owner/User Discovery; T1057 Process Discovery; T1082 System Information Discovery

exfiltration

T1041 Exfiltration Over C2 Channel

execution

T1053 Scheduled Task/Job; T1053.005 Scheduled Task; T1059 Command and Scripting Interpreter; T1059.001 PowerShell; T1059.003 Windows Command Shell; T1059.005 Visual Basic; T1106 Native API; T1204 User Execution; T1204.002 Malicious File

collection

T1056 Input Capture; T1056.001 Keylogging; T1113 Screen Capture; T1115 Clipboard Data; T1125 Video Capture

command-and-control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1568 Dynamic Resolution

defense-impairment

T1553 Subvert Trust Controls; T1553.005 Mark-of-the-Web Bypass

credential-access

T1555.003 Credentials from Web Browsers

initial-access

T1566 Phishing; T1566.001 Spearphishing Attachment

resource-development

T1584.001 Domains; T1588 Obtain Capabilities; T1608 Stage Capabilities; T1608.001 Upload Malware

Remediation for DEAD#VAX AsyncRAT Campaign

Immediate actions

  • Block VHD/VHDX file attachments and downloads at email gateway and web proxy level
  • Disable Windows native VHD auto-mounting via Group Policy or registry (HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer)
  • Block IPFS gateway domains at DNS/proxy level: w3s.link, ipfs.io, cloudflare-ipfs.com, dweb.link, gateway.pinata.cloud
  • Block WSF/VBS/BAT execution from mounted removable drives and VHD volumes via AppLocker/WDAC
  • Monitor for renamed PowerShell executables (mbs.exe pattern) via process creation auditing

Workarounds

  • Disable auto-mount of VHD files: assoc .vhd= and assoc .vhdx= (removes file association)
  • Configure AppLocker to block script execution from non-standard locations
  • Enable Windows Defender Credential Guard
  • Deploy network-level IPFS gateway blocking

Longer-term hardening

  • Deploy PowerShell Constrained Language Mode to prevent Add-Type C# compilation and native API access
  • Enable PowerShell Script Block Logging and Module Logging for fileless attack detection
  • Implement Attack Surface Reduction (ASR) rules to block process injection via CreateRemoteThread
  • Deploy Credential Guard to protect against credential theft via AsyncRAT StealerLib
  • Implement email authentication (SPF, DKIM, DMARC) to detect domain spoofing (procoms.com impersonation)
  • Monitor scheduled task creation for hidden tasks with randomized names
  • Deploy memory-scanning EDR with in-memory shellcode detection capabilities
  • Block outbound connections to known AsyncRAT C2 infrastructure

Weaknesses (CWE) in DEAD#VAX AsyncRAT Campaign

CWE-434

Timeline of DEAD#VAX AsyncRAT Campaign

  • AsyncRAT open-source RAT created by NYAN-x-CAT on GitHub under MIT license. C# .NET Framework, modular plugin architecture, encrypted C2. Becomes widely adopted by threat actors. Source: https://github.com/NYAN-x-CAT/AsyncRAT-C-Sharp
  • AsyncRAT cataloged as MITRE ATT&CK Software S1087 with documented techniques: Debugger Evasion (T1622), Dynamic Resolution (T1568), Hidden Window (T1564.003), Keylogging (T1056.001), Scheduled Task (T1053.005), Screen/Video Capture (T1113/T1125), Sandbox Evasion (T1497.001). Source: https://attack.mitre.org/software/S1087/
  • DEAD#VAX campaign becomes active. Phishing emails impersonating Progressive Components (procoms.com) deliver IPFS-hosted VHD files containing multi-stage AsyncRAT loader. Source: https://www.securonix.com/blog/deadvax-threat-research-security-advisory/
  • Securonix Threat Research publishes detailed code-level analysis of DEAD#VAX campaign: 5-stage infection chain, VHD MotW bypass, 4-layer deobfuscation engine, self-parsing batch scripts, fileless PowerShell injection, AsyncRAT shellcode delivery into trusted processes. Researchers: Akshay Gaikwad, Shikha Sangwan, Aaron Beardslee. Source: https://www.securonix.com/blog/deadvax-threat-research-security-advisory/
  • Securonix publishes formal security advisory for DEAD#VAX campaign, expanding distribution of threat intelligence to broader community. Source: https://www.securonix.com/blog/
  • Securonix includes DEAD#VAX in 2025 Annual Threat Intelligence Insights report as example of modern fileless malware tradecraft evolution. Source: https://www.securonix.com/blog/securonix-threat-labs-2025-annual-autonomous-threat-sweeper-intelligence-insights/
  • As of 2026-05-29, DEAD#VAX remains a viable, unmitigated threat: no CVE/patch applies, IPFS hosting makes takedowns "practically impossible," operators stay unattributed/undisrupted, and AsyncRAT ranks as a top-2 active malware family per Maltiverse. No fresh waves of this specific Securonix-tracked campaign are confirmed past Feb 2026 and no successor supersedes it, warranting MONITORING.

Sources cited for DEAD#VAX AsyncRAT Campaign

Detection coverage for TL-2026-0092

As of 2026-01-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0092 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
26 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats