New DeepLoad Malware Uses ClickFix and AI-Generated Evasion to Breach Enterprise Networks
ID: 240f48ec-0c6b-520d-8818-0d57b2b6c1cb
STIX ID: report--240f48ec-0c6b-520d-8818-0d57b2b6c1cb
Feed Name: cybersecurityNews.com
DeepLoad is a sophisticated enterprise-targeting malware campaign that tricks users into pasting a PowerShell command to install a persistent loader which uses mshta.exe to fetch obfuscated payloads, compiles an in-memory C# injector, performs APC-based process injection into LockAppHost.exe, plants hidden WMI event subscriptions for reinfection, drops a credential stealer (filemanager.exe), installs a malicious browser extension to capture passwords/session tokens, and writes disguised installer files to USB drives; defenders are advised to audit and clear WMI subscriptions, rotate credentials, remove unapproved extensions, audit USB media, enable PowerShell Script Block Logging, and shift to behavioral/EDR detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
