Threats · 167 days ago
ReliaQuest found a campaign using the ClickFix social-engineering lure to run a PowerShell command via mshta.exe and deploy a new loader named DeepLoad. DeepLoad uses heavy junk-code obfuscation that researchers say was likely AI-generated, injects into processes and drops a temporary DLL to evade file-based scanning, immediately harvests browser passwords and session tokens, disables PowerShell history, and establishes WMI persistence to enable stealth reinfection after about three days.
4 sources covering this story
New DeepLoad Malware Dropped in ClickFix Attacks
The malware steals credentials, installs a malicious browser extension, and can spread via USB drives.
AI-Powered 'DeepLoad' Steals Credentials, Evades Detection
The massive amount of junk code that hides the malware's logic from security scans was almost certainly generated by AI, researchers say.
DeepLoad Malware Uses ClickFix and WMI Persistence to Steal Browser Credentials
DeepLoad exploits ClickFix and WMI persistence to steal credentials, enabling stealth reinfection after three days.
DeepLoad Malware Combines ClickFix With AI-Code to Avoid Detection
Researchers at ReliaQuest warn of persistent malware campaign targeting enterprise credentials
Part of the PlainSec briefing for 2026-03-31