Dead#Vax
Dead#Vax is a sophisticated, multistage malware campaign that abuses legitimate Windows features and fileless execution mechanisms. Reported delivery involves phishing emails impersonating legitimate businesses that contain links to virtual hard disk (VHD) files hosted on IPFS. When a victim opens the VHD, the execution chain triggers Windows Script Files, obfuscated self-parsing batch scripts, and PowerShell loaders. Securonix analysts reported the chain supports encrypted data siphoning and conceals critical strings and execution logic. The intrusion ultimately deploys AsyncRAT, which is used for credential theft/exfiltration, data exfiltration, surveillance, and enabling follow-on intrusions.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Techniques & procedures
12 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
2 techniques
Initial Access
Execution
3 techniques
Execution
Privilege Escalation
1 technique
Privilege Escalation
Stealth
4 techniques
Stealth
...obfuscated batch scripts... PowerShell loaders for encrypted data siphoning and critical string and execution logic concealment...
Defense Impairment
1 technique
Defense Impairment
Discovery
1 technique
Discovery
Command and Control
1 technique
Command and Control
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Multi-stage malware delivery chain using VHD-based delivery and self-parsing batch scripts to deploy in-memory shellcode.
“Analyzing Dead#Vax: Analyzing Multi-Stage VHD Delivery and Self-Parsing Batch Scripts to Deploy In-Memory Shellcode”
A multistage, fileless malware campaign delivered via phishing emails linking to VHD files hosted on IPFS; execution chains through Windows Script Files, obfuscated batch scripts, and PowerShell loaders to enable encrypted data siphoning and conceal execution logic, ultimately delivering a secondary payload.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.