logo

DeepLoad Malware Explained: ClickFix Delivery and Password Stealing

ID: bebd4ad5-1be2-56b9-ac88-060c2063e022

STIX ID: report--bebd4ad5-1be2-56b9-ac88-060c2063e022

Feed Name: Resources-2

Threat Score
75/100

Date Published: 2026-05-22

Date Updated: 2026-07-22

Author: [email protected] (Umut Bayram)

...
...

This report analyzes DeepLoad, a fileless loader observed in March 2026 that leverages ClickFix social engineering to execute an obfuscated PowerShell payload in memory, uses APC-based injection into trusted Windows binaries (e.g., LockAppHost.exe) to evade detection, and immediately performs credential theft via a separate stealer (filemanager.exe) and a malicious browser extension; it also propagates via USB by dropping numerous .lnk shortcuts to re-trigger infection and includes Picus simulation IDs for validating defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.