Threats & Adversaries · Credential Theft
Windows DeepLoad loader steals browser credentials and hides with AI-like junk code ReliaQuest found a campaign using the ClickFix social-engineering lure to run a PowerShell command via mshta.exe and deploy a new loader named DeepLoad. DeepLoad uses heavy junk-code obfuscation that researchers say was likely AI-generated, injects into processes and drops a temporary DLL to evade file-based scanning, immediately harvests browser passwords and session tokens, disables PowerShell history, and establishes WMI persistence to enable stealth reinfection after about three days.
4 sources · Apr 1
Timeline Sources Apr 1 SecurityWeek
New DeepLoad Malware Dropped in ClickFix Attacks
The malware steals credentials, installs a malicious browser extension, and can spread via USB drives.
original Mar 30 Dark Reading
AI-Powered 'DeepLoad' Steals Credentials, Evades Detection
The massive amount of junk code that hides the malware's logic from security scans was almost certainly generated by AI, researchers say.
original Mar 30 The Hacker News
DeepLoad Malware Uses ClickFix and WMI Persistence to Steal Browser Credentials
DeepLoad exploits ClickFix and WMI persistence to steal credentials, enabling stealth reinfection after three days.
original Vendor digest: Microsoft
Part of the PlainSec briefing for 2026-03-31
Every edition of this story: Windows DeepLoad loader steals browser credentials and hides with AI-like junk code
More from today
Threats & Adversaries · Credential Theft
Windows DeepLoad loader steals browser credentials and hides with AI-like junk code ReliaQuest found a campaign using the ClickFix social-engineering lure to run a PowerShell command via mshta.exe and deploy a new loader named DeepLoad. DeepLoad uses heavy junk-code obfuscation that researchers say was likely AI-generated, injects into processes and drops a temporary DLL to evade file-based scanning, immediately harvests browser passwords and session tokens, disables PowerShell history, and establishes WMI persistence to enable stealth reinfection after about three days.
4 sources · Apr 1
Timeline Sources Apr 1 SecurityWeek
New DeepLoad Malware Dropped in ClickFix Attacks
The malware steals credentials, installs a malicious browser extension, and can spread via USB drives.
original Mar 30 Dark Reading
AI-Powered 'DeepLoad' Steals Credentials, Evades Detection
The massive amount of junk code that hides the malware's logic from security scans was almost certainly generated by AI, researchers say.
original Mar 30 The Hacker News
DeepLoad Malware Uses ClickFix and WMI Persistence to Steal Browser Credentials
DeepLoad exploits ClickFix and WMI persistence to steal credentials, enabling stealth reinfection after three days.
original Vendor digest: Microsoft
Part of the PlainSec briefing for 2026-03-31
Every edition of this story: Windows DeepLoad loader steals browser credentials and hides with AI-like junk code
More from today