ReliaQuest researchers reported that a credential-stealing malware campaign dubbed DeepLoad has been compromising enterprise IT environments through ClickFix/QuickFix-style social engineering. Attackers used fake browser prompts and error pages to trick users into running a malicious command, which launched a loader engineered to bypass multiple security tools. Researchers said the malware used heavily padded code and execution tied to a Windows lock-screen process, indicating AI-assisted obfuscation at multiple stages to reduce the effectiveness of static, file-based detection.
Once installed, DeepLoad enabled real-time keylogging, stole credentials, spread to connected USB drives, and maintained hidden persistence that allowed the malware to re-execute days after apparent cleanup. The campaign's ability to survive standard remediation has raised concern that AI-generated variation is making malware more adaptable and harder to detect. Researchers urged defenders to emphasize behavioral and runtime detection over traditional static analysis to identify similar threats earlier.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
In its reporting on the campaign, ReliaQuest warned that AI-generated variation is reducing the effectiveness of static, file-based detection. The researchers advised defenders to prioritize behavioral and runtime detection methods to identify DeepLoad and similar threats earlier.
ReliaQuest researchers reported that DeepLoad used suspected AI-assisted obfuscation at multiple stages to evade security tools, including heavily padded code and execution behind a Windows lock screen process. They also found the malware could keylog in real time, spread to connected USB drives, and re-execute days after cleanup through a hidden persistence mechanism.
A credential-stealing malware campaign dubbed DeepLoad was observed infecting enterprise business IT environments. Attackers used QuickFix/ClickFix-style social engineering, including fake browser prompts and error pages, to trick users into launching the malware loader.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.