Windows DeepLoad loader steals browser credentials and hides with AI-like junk code
ReliaQuest found a campaign using the ClickFix social-engineering lure to run a PowerShell command via mshta.exe and deploy a new loader named DeepLoad. DeepLoad uses heavy junk-code obfuscation that researchers say was likely AI-generated, injects into processes and drops a temporary DLL to evade file-based scanning, immediately harvests browser passwords and session tokens, disables PowerShell history, and establishes WMI persistence to enable stealth reinfection after about three days.