Researchers reported two newly documented Windows malware loaders, Kiss Loader and DeepLoad, in emerging campaigns that rely on stealthy execution and social engineering to deliver follow-on malware. G DATA said Kiss Loader was delivered through phishing emails using Internet Shortcut (.url) files disguised as PDFs, which retrieved payloads through a TryCloudflare tunnel and an exposed WebDAV repository. The loader established persistence, showed a decoy PDF, downloaded additional components, and deployed malware including VenomRAT and a .NET Reactor-protected sample identified as Kryptik.
DeepLoad was distributed through the ClickFix technique, tricking victims into pasting malicious PowerShell into the Windows Run dialog before launching mshta.exe and obfuscated PowerShell to execute the infection chain. Researchers said the malware used APC injection, AI-assisted obfuscation, randomized Add-Type DLL compilation, PowerShell history suppression, abuse of legitimate processes such as LockAppHost.exe, and WMI event subscriptions for persistence and reinfection. Its objectives included browser credential theft, deployment of a malicious browser extension to capture logins, and propagation through removable media with deceptive .lnk filenames, while Kiss Loader similarly used Early Bird APC injection into explorer.exe to evade detection and run payloads in memory.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Researchers disclosed a separate malware campaign distributing a previously undocumented loader named DeepLoad via the ClickFix social engineering technique. The malware used obfuscated PowerShell, mshta.exe, APC injection, removable-media propagation, and WMI event subscriptions to steal browser credentials and maintain persistence.
While investigating Kiss Loader, G DATA reported direct interaction with the threat actor, who confirmed that the use of Early Bird APC injection was intentional. This provided rare confirmation of the operator's deliberate evasion design.
During analysis of the March 2026 campaign, researchers found Kiss Loader fetching payloads through a TryCloudflare tunnel and an exposed WebDAV repository, then establishing persistence, showing a decoy PDF, and deploying malware including VenomRAT and a Kryptik sample. Its primary evasion technique was Early Bird APC injection into explorer.exe using Donut-generated shellcode.
G DATA identified a newly discovered malware loader called Kiss Loader and said the campaign was first observed in early March 2026. The operation used phishing-delivered Windows Internet Shortcut files disguised as PDFs to target Windows users.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.