logo

DeepLoad Malware Combines ClickFix With AI-Generated Code to Avoid Detection

ID: 55fe7290-c231-59b9-92e0-9889b96ac157

STIX ID: report--55fe7290-c231-59b9-92e0-9889b96ac157

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2026-03-30

Date Updated: 2026-04-22

...
...

Researchers at ReliaQuest uncovered the DeepLoad campaign, an active credential-stealing malware operation that uses ClickFix social engineering to trick users into executing malicious commands, employs AI-generated code padding to evade detection, hides inside Windows lock screen processes, abuses WMI for hidden persistence (including a three-day re-infection mechanism), and can propagate via USB; defenders are advised to enable PowerShell Script Block Logging, audit WMI subscriptions, and reset credentials after compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.