DeepLoad Malware Pairs ClickFix Delivery with AI-Generated Evasion
ID: b91378cd-2ffc-546c-b2de-ad0b5b90cbe7
STIX ID: report--b91378cd-2ffc-546c-b2de-ad0b5b90cbe7
Feed Name: ReliaQuest Blog
ReliaQuest reports on the "DeepLoad" fileless malware campaign delivered via "ClickFix" social engineering that rapidly achieves persistent, credential-stealing access by using AI-like obfuscation, in-memory APC injection into LockAppHost.exe, a separate credential stealer (filemanager.exe) and browser extension, USB propagation, and WMI subscription-based reinfection; the report emphasizes runtime behavioral detection (PowerShell Script Block Logging, EDR telemetry), explicit WMI subscription auditing, rotating exposed credentials, and provides IOCs and detection recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
