Researchers reported that the Dead#Vax malware campaign delivers payloads through multi-stage VHD disk image files and heavily obfuscated batch scripts that parse themselves to reconstruct and launch shellcode directly in memory. The intrusion chain relies on fileless execution techniques in Windows, reducing on-disk artifacts and complicating detection, while the staged delivery mechanism helps operators evade traditional security controls.
Public reporting said the malware uses self-parsing scripts and in-memory shellcode deployment to maintain stealth across infected systems, with Securonix warning that the campaign abuses native Windows functionality as part of its execution flow. The activity was described as a sophisticated, multi-stage operation designed to blend into normal system behavior, underscoring the need for defenders to monitor suspicious use of virtual disk images, script interpreters, and memory-resident execution patterns.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Securonix published research on the Dead#Vax malware campaign, describing a multi-stage infection chain using VHD delivery, self-parsing batch scripts, and in-memory shellcode execution. The reporting characterized the activity as abusing Windows fileless execution techniques.
Ctrl-Alt-Intel reported a persistent Chinese cyber operation directed at Vietnamese universities. The references do not provide a specific start date for the activity, only that the campaign was documented publicly in the report.
3 references tracked. Mallory keeps watching after this page renders.
securonix.com
Open sourcesiliconangle.com
Open sourcectrlaltint3l.github.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.