Minacce · 181 giorni fa
ReliaQuest ha scoperto una campagna che utilizza l’esca di social engineering ClickFix per eseguire un comando PowerShell tramite mshta.exe e distribuire un nuovo loader chiamato DeepLoad. DeepLoad utilizza una pesante obfuscazione con codice spazzatura che i ricercatori dicono sia probabilmente generato da AI, si injecta nei processi e rilascia una DLL temporanea per eludere la scansione basata sui file, raccoglie immediatamente le password del browser e i token di sessione, disabilita la cronologia di PowerShell e stabilisce persistenza tramite WMI per consentire una reinfezione furtiva dopo circa tre giorni.
4 fonti che coprono questa storia
New DeepLoad Malware Dropped in ClickFix Attacks
The malware steals credentials, installs a malicious browser extension, and can spread via USB drives.
AI-Powered 'DeepLoad' Steals Credentials, Evades Detection
The massive amount of junk code that hides the malware's logic from security scans was almost certainly generated by AI, researchers say.
DeepLoad Malware Uses ClickFix and WMI Persistence to Steal Browser Credentials
DeepLoad exploits ClickFix and WMI persistence to steal credentials, enabling stealth reinfection after three days.
DeepLoad Malware Combines ClickFix With AI-Code to Avoid Detection
Researchers at ReliaQuest warn of persistent malware campaign targeting enterprise credentials
Riepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-03-31