logo

DeepLoad Malware Pairs ClickFix Delivery with AI-Generated Evasion

ID: b91378cd-2ffc-546c-b2de-ad0b5b90cbe7

STIX ID: report--b91378cd-2ffc-546c-b2de-ad0b5b90cbe7

Feed Name: ReliaQuest Blog

Threat Score
80/100

Date Published: 2026-03-30

Date Updated: 2026-04-29

...
...

ReliaQuest reports on the "DeepLoad" fileless malware campaign delivered via "ClickFix" social engineering that rapidly achieves persistent, credential-stealing access by using AI-like obfuscation, in-memory APC injection into LockAppHost.exe, a separate credential stealer (filemanager.exe) and browser extension, USB propagation, and WMI subscription-based reinfection; the report emphasizes runtime behavioral detection (PowerShell Script Block Logging, EDR telemetry), explicit WMI subscription auditing, rotating exposed credentials, and provides IOCs and detection recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.