AI-Powered 'DeepLoad' Malware Steals Credentials, Evades Detection
ID: bd19340f-33d7-5387-8ed9-d7eae022f158
STIX ID: report--bd19340f-33d7-5387-8ed9-d7eae022f158
Feed Name: Dark Reading
ReliaQuest identified a new credential‑stealing malware family dubbed "DeepLoad" that immediately harvests stored browser passwords and live keystrokes via a standalone stealer and a malicious browser extension. The campaign uses ClickFix social engineering to run mshta and a heavily obfuscated PowerShell loader (likely AI-padded), injects payloads into LockAppHost.exe via dynamically compiled DLLs, persists using scheduled tasks and WMI event subscriptions, and can spread to USB drives; standard file-based cleanup may be insufficient, so organizations should remove WMI subscriptions, enable PowerShell logging and behavioral monitoring, and rotate exposed credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
