DeepLoad Malware Explained: ClickFix Delivery and Password Stealing
ID: bebd4ad5-1be2-56b9-ac88-060c2063e022
STIX ID: report--bebd4ad5-1be2-56b9-ac88-060c2063e022
Feed Name: Resources-2
This report analyzes DeepLoad, a fileless loader observed in March 2026 that leverages ClickFix social engineering to execute an obfuscated PowerShell payload in memory, uses APC-based injection into trusted Windows binaries (e.g., LockAppHost.exe) to evade detection, and immediately performs credential theft via a separate stealer (filemanager.exe) and a malicious browser extension; it also propagates via USB by dropping numerous .lnk shortcuts to re-trigger infection and includes Picus simulation IDs for validating defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
