Windows DeepLoad loader steals browser credentials and hides with AI-like junk code

ReliaQuest found a campaign using the ClickFix social-engineering lure to run a PowerShell command via mshta.exe and deploy a new loader named DeepLoad. DeepLoad uses heavy junk-code obfuscation that researchers say was likely AI-generated, injects into processes and drops a temporary DLL to evade file-based scanning, immediately harvests browser passwords and session tokens, disables PowerShell history, and establishes WMI persistence to enable stealth reinfection after about three days.

Part of the PlainSec briefing for 2026-03-31

Sources