# DEAD#VAX AsyncRAT Campaign — IPFS-Hosted VHD Phishing, 5-Stage Fileless Infection Chain, Mark-of-the-Web Bypass, Self-Parsing Batch Scripts, 4-Layer PowerShell Deobfuscation, In-Memory Shellcode Injection into Trusted Processes

> DEAD#VAX is a sophisticated multi-stage malware campaign tracked by Securonix Threat Research that delivers AsyncRAT via IPFS-hosted VHD phishing lures. The attack chain progresses through VHD mounting (bypassing Mark-of-the-Web), WSF script execution, heavily obfuscated batch scripts with self-parsing logic, fileless PowerShell loaders with 4-layer deobfuscation, and in-memory shellcode injection into trusted Microsoft-signed processes — never writing a decrypted payload to disk.

- **Published:** 2026-01-14T12:00:00Z
- **Last reviewed:** 2026-01-14T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0092
- **ID:** TL-2026-0092
- **Severity:** HIGH
- **Category:** PHISHING
- **Status:** MONITORING
- **Detections:** 9 · **IOCs:** 26 (full data via the Threadlinqs MCP server — Purple tier)

## Description

DEAD#VAX is a multi-stage, fileless malware campaign documented by Securonix Threat Research (researchers Akshay Gaikwad, Shikha Sangwan, Aaron Beardslee, published January 14, 2026, advisory published February 4, 2026). The campaign delivers AsyncRAT through an elaborate 5-stage infection chain designed to evade traditional security controls at every step.

**Stage 1 — Initial Access (Phishing + IPFS-hosted VHD):** The attack begins with spear-phishing emails impersonating Progressive Components (procoms.com), a legitimate tooling supplier. The actual sending domain is mingyitc.com (likely compromised). The email creates artificial urgency with a 2-day response deadline and includes a fake 'Virus scan completed' banner. The download link points to a VHD file hosted on IPFS via the w3s.link gateway (bafybeiaj6jw2xhbppgji757tn3hg5uu6splaa5gyydkwnzwprzakcp44ve.ipfs.w3s.link). IPFS content-addressed hosting makes traditional URL-based takedowns ineffective — the file persists as long as any IPFS node pins it. At time of analysis, the phishing emails scored 0/0 on VirusTotal.

**Stage 2 — VHD Mount + MotW Bypass:** When the user double-clicks the downloaded VHD file, Windows 10/11 natively mounts it as a new logical drive. Files inside the VHD do NOT inherit the Mark-of-the-Web (MotW) from the container, appearing as local files on a local disk. The mounted drive contains a WSF script with a double extension (purchaseorder...pdf.wsf) designed to trick users into thinking it's a PDF. SmartScreen does not scan files from mounted VHDs as aggressively.

**Stage 3 — WSF → Batch Script Execution:** The WSF file is heavily obfuscated with fragmented string variables. It uses Msxml2.DOMDocument.3.0 COM objects for Base64 decoding (avoiding standard functions) and a rolling XOR decryption with key '4qrttc9sl-sdnYziCVHb8g'. The decrypted output is a batch file written to %TEMP%\temp with a random alphanumeric filename (MXVT60Xx6um7nRNl.bat).

**Stage 4 — Obfuscated Batch with Self-Parsing Logic:** The batch file uses environment variable explosion — thousands of SET commands with random variable names that map to individual characters/fragments. After deobfuscation, the batch performs: (1) Anti-analysis checks: admin privilege check via 'net session', VMware detection via WMI Win32_ComputerSystem/BIOS, RAM check (exits if <3GB — anti-sandbox), checks for analyst artifacts ('VBE', 'mapping.csv'). (2) Self-parsing: copies itself to rEgX.cmd, runs mbs.exe (renamed powershell.exe), reads its own content looking for lines starting with '@' to extract the hidden Base64 payload appended at the end. (3) Decryption: Base64 decode → rolling XOR with key 'md' → Invoke-Expression for in-memory execution. The decrypted code never touches disk.

**Stage 5 — Fileless PowerShell Loader + AsyncRAT Injection:** The final PowerShell stage is a sophisticated process injector with: (1) 4-layer string deobfuscation engine (fXZBcHpNzP): Unicode pollution removal → Base64 decode → rolling XOR → ROT character shift. (2) Native API access via Add-Type C# compilation: OpenProcess, VirtualAllocEx, WriteProcessMemory, CreateRemoteThread, ReadProcessMemory, VirtualQueryEx. (3) Target process enumeration: RuntimeBroker.exe, OneDrive.exe, taskhostw.exe, sihost.exe — all Microsoft-signed trusted processes. (4) Reinfection marker scanner: checks for byte sequence DEADBECAFEBAEF in target process memory to prevent duplicate injection. (5) Persistence: hidden scheduled task + VBS launcher with rotation logic (self-healing if artifacts removed, generates new randomized task names). (6) Payload stored at C:\ProgramData\IntelDriver\boot64x.w as noise-polluted Base64 data. (7) ~71KB x64 shellcode with entropy >7.7, no PE header — pure encrypted shellcode.

**AsyncRAT Final Payload:** Dynamic analysis confirmed the shellcode deploys a fully functional AsyncRAT implant with: keylogging, screen/webcam capture, clipboard monitoring, file system access, remote command execution, encrypted C2 (TCP/TLS), modular plugin architecture (StealerLib credential theft), and asynchronous command handling for long-running surveillance.

AsyncRAT (MITRE S1087) is an open-source C# RAT created by NYAN-x-CAT, available on GitHub under MIT license. It is widely abused by both low-skill actors and organized groups due to its modular design and extensive feature set. The DEAD#VAX campaign's sophistication (5-stage chain, fileless execution, 4-layer obfuscation, reinfection prevention, persistence rotation) suggests a more capable threat actor than typical AsyncRAT users.

## MITRE ATT&CK

- T1566 Phishing
- T1204 User Execution
- T1059 Command and Scripting Interpreter
- T1106 Native API
- T1053 Scheduled Task/Job
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1553 Subvert Trust Controls
- T1036 Masquerading
- T1055 Process Injection
- T1497 Virtualization/Sandbox Evasion
- T1564 Hide Artifacts
- T1070 Indicator Removal
- T1056 Input Capture
- T1082 System Information Discovery
- T1033 System Owner/User Discovery
- T1057 Process Discovery
- T1622 Debugger Evasion
- T1113 Screen Capture
- T1125 Video Capture
- T1071 Application Layer Protocol
- T1568 Dynamic Resolution
- T1105 Ingress Tool Transfer
- T1041 Exfiltration Over C2 Channel
- T1608 Stage Capabilities
- T1588 Obtain Capabilities
- T1566.001 Spearphishing Attachment
- T1204.002 Malicious File
- T1059.001 PowerShell
- T1059.003 Windows Command Shell
- T1059.005 Visual Basic
- T1053.005 Scheduled Task
- T1553.005 Mark-of-the-Web Bypass
- T1036.007 Double File Extension
- T1036.003 Rename Legitimate Utilities
- T1497.001 System Checks
- T1564.003 Hidden Window
- T1056.001 Keylogging
- T1608.001 Upload Malware
- T1620 Reflective Code Loading

## Sources

- [Securonix Threat Research: Dead#Vax — Multi-Stage VHD Delivery](https://www.securonix.com/blog/deadvax-threat-research-security-advisory/)
- [MITRE ATT&CK — AsyncRAT (S1087)](https://attack.mitre.org/software/S1087/)
- [AsyncRAT GitHub — Open-Source C# RAT](https://github.com/NYAN-x-CAT/AsyncRAT-C-Sharp)
- [Securonix 2025 Annual Threat Intelligence Report](https://www.securonix.com/blog/securonix-threat-labs-2025-annual-autonomous-threat-sweeper-intelligence-insights/)
- [Telefónica Tech — Snip3 AsyncRAT Investigation](https://telefonicatech.com/blog/snip3-investigacion-malware)
- [IPFS Content Addressing Documentation](https://docs.ipfs.tech/concepts/content-addressing/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0092
