Threats & Adversaries · Credential Theft

Windows DeepLoad loader steals browser credentials and hides with AI-like junk code

ReliaQuest found a campaign using the ClickFix social-engineering lure to run a PowerShell command via mshta.exe and deploy a new loader named DeepLoad. DeepLoad uses heavy junk-code obfuscation that researchers say was likely AI-generated, injects into processes and drops a temporary DLL to evade file-based scanning, immediately harvests browser passwords and session tokens, disables PowerShell history, and establishes WMI persistence to enable stealth reinfection after about three days.

4 sources · Apr 1

Timeline

Sources

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-03-31

Every edition of this story: Windows DeepLoad loader steals browser credentials and hides with AI-like junk code

More from today