logo

What Is the BabaDeda Loader? Analysis of a New ClickFix Malware Campaign 

ID: a2555f22-417d-5af7-b199-f85f2fefc052

STIX ID: report--a2555f22-417d-5af7-b199-f85f2fefc052

Feed Name: Morphisec Blog

Threat Score
75/100

Date Published: 2026-06-16

Date Updated: 2026-06-16

...
...

Morphisec researchers observed active BabaDeda loader campaigns (April 2026) targeting education and financial organizations; the evolved loader uses social-engineered PowerShell execution, modular staging, external payload storage, DLL sideloading, and in-memory execution to deliver information stealers and remote access trojans (DanaBot, SectopRAT). The report emphasizes the framework's stealth and evasion techniques that defeat file- and signature-based detection and recommends prevention-first defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.