logo

DeepLoad Malware Uses ClickFix and WMI Persistence to Steal Browser Credentials

ID: 4e437754-3abe-576b-bfc1-078844916084

STIX ID: report--4e437754-3abe-576b-bfc1-078844916084

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-03-30

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

A recent campaign leverages a ClickFix social-engineering lure and malicious shortcuts to deliver two loaders: DeepLoad — a sophisticated PowerShell-based loader that uses AI-assisted obfuscation, in-memory APC injection, runtime C# DLL compilation, WMI persistence, USB spread, and a malicious browser extension to steal credentials — and Kiss Loader, distributed via URL shortcuts that fetch a Python loader and deploy Venom RAT via APC injection. Both aim to evade detection, maintain persistence, and exfiltrate credentials across infected hosts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.