logo

AI-Powered 'DeepLoad' Malware Steals Credentials, Evades Detection

ID: bd19340f-33d7-5387-8ed9-d7eae022f158

STIX ID: report--bd19340f-33d7-5387-8ed9-d7eae022f158

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2026-03-30

Date Updated: 2026-04-22

Author: Jai Vijayan

...
...

ReliaQuest identified a new credential‑stealing malware family dubbed "DeepLoad" that immediately harvests stored browser passwords and live keystrokes via a standalone stealer and a malicious browser extension. The campaign uses ClickFix social engineering to run mshta and a heavily obfuscated PowerShell loader (likely AI-padded), injects payloads into LockAppHost.exe via dynamically compiled DLLs, persists using scheduled tasks and WMI event subscriptions, and can spread to USB drives; standard file-based cleanup may be insufficient, so organizations should remove WMI subscriptions, enable PowerShell logging and behavioral monitoring, and rotate exposed credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.