Tag: DeepLoad Malware

DeepLoad Malware Uses ClickFix and WMI Persistence to Steal Browser Credentials
News

DeepLoad Malware Uses ClickFix and WMI Persistence to Steal Browser Credentials

A new operation has used the ClickFix social engineering technique to spread DeepLoad, a malware loader that was previously unreported. In a report shared with The Hacker News, ReliaQuest researchers Thassanai McCabe and Andrew Currie stated that while credential theft begins instantly and captures passwords and sessions even if the primary loader is blocked, it probably uses AI-assisted obfuscation and process injection to avoid static scanning. The attack chain begins with a ClickFix bait that deceives users into executing PowerShell commands by pasting the command into the Windows Run dialog under the guise of fixing a nonexistent problem. This then downloads and launches an obfuscated PowerShell loader using "mshta.exe," a valid Windows tool. For its part, it has been discove...