DeepLoad Malware Combines ClickFix With AI-Generated Code to Avoid Detection
ID: 55fe7290-c231-59b9-92e0-9889b96ac157
STIX ID: report--55fe7290-c231-59b9-92e0-9889b96ac157
Feed Name: Infosecurity Magazine (News)
Researchers at ReliaQuest uncovered the DeepLoad campaign, an active credential-stealing malware operation that uses ClickFix social engineering to trick users into executing malicious commands, employs AI-generated code padding to evade detection, hides inside Windows lock screen processes, abuses WMI for hidden persistence (including a three-day re-infection mechanism), and can propagate via USB; defenders are advised to enable PowerShell Script Block Logging, audit WMI subscriptions, and reset credentials after compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
