DeepLoad is a Windows-focused credential-stealing malware family delivered primarily through ClickFix social-engineering lures in enterprise environments. Victims are tricked into pasting and executing attacker-supplied commands through trusted Windows interfaces, after which the infection chain uses legitimate system components and heavily obfuscated PowerShell to retrieve and execute follow-on payloads. DeepLoad has been characterized as largely fileless and notable for likely AI-assisted obfuscation, with large volumes of junk code used to hinder static analysis and signature-based detection.
Once executed, DeepLoad establishes persistence through scheduled tasks and has also been observed using Windows Management Instrumentation event subscriptions to survive remediation and re-execute after apparent cleanup. It employs in-memory decryption and process injection into a legitimate Windows lock-screen-related process to reduce on-disk artifacts and blend into normal system activity. Reported post-compromise behavior includes theft of stored credentials, capture of newly entered credentials through keylogging or a malicious browser extension, and continued credential theft even when parts of the initial loader chain are disrupted.
DeepLoad has also been associated with propagation to connected USB media, increasing the risk of follow-on infections beyond the initially compromised host. The malware’s tradecraft emphasizes defense evasion through abuse of legitimate Windows utilities, randomized or dynamically generated components, suppression of forensic visibility, and runtime execution patterns that make behavioral detection more effective than file-based scanning. DeepLoad has been reported in campaigns affecting enterprise business IT environments rather than a single vertical, with the strongest evidence pointing to credential theft and persistence as its core operational goals.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
In this campaign, this one command was enough to establish persistent, reboot-surviving access by creating a scheduled task configured to repeatedly re-execute the loader.
The leading technique was ClickFix, which involves tricking users into pasting the attacker’s commands and scripts into trusted system dialogs...
This command is used to execute PowerShell code and retrieve infostealers or other malware payloads which then secretly compromise the victim.
ClickFix is a potent attack vector, because it socially engineers the victim into pasting attacker-supplied commands into trusted system dialogs. In ClickFix-style attacks, the user enters the command, which bypasses many anti-virus and cyber defense tools that categorize the action as legitimate.
In this campaign, this one command was enough to establish persistent, reboot-surviving access by creating a scheduled task configured to repeatedly re-execute the loader.
In this campaign, this one command was enough to establish persistent, reboot-surviving access by creating a scheduled task configured to repeatedly re-execute the loader.
our threat intelligence team identified a separate, previously undocumented fileless delivery system we track as “SpectrePaste” ... SpectrePaste v2 utilized spec-driven development, transforming a basic powershell delivery script into a fileless, reflective loading system.
a ClickFix loader use likely AI-generated obfuscation to deliver 'Deepload' malware, burying its real logic under thousands of meaningless variable assignments to defeat static scanning
To carry out the injection DeepLoad uses a PowerShell feature called Add-Type to generate a temporary Dynamic Link Library (DLL) that is dropped into the compromised computer's Temp directory.
ReliaQuest urged organizations to perform ongoing behavioral analysis of computers on their networks to catch the malware in the act, given that its fileless operations can bypass more traditional static defenses.
our threat intelligence team identified a separate, previously undocumented fileless delivery system we track as “SpectrePaste” ... SpectrePaste v2 utilized spec-driven development, transforming a basic powershell delivery script into a fileless, reflective loading system.
Through asynchronous procedure call (APC) injection, the loader places shellcode into that process’s memory and triggers execution on resume...
The malware also disables PowerShell command history to cover its own tracks.
The actual logic — a short XOR decryption routine — sits at the bottom and decrypts shellcode in memory, so no decoded payload touches disk.
A malicious browser extension captures passwords and session tokens as users type them, persisting across sessions until removed.
Researchers have uncovered a new malware strain capable of stealing credentials immediately after gaining a foothold on a victim network, capturing both stored browser passwords and live keystrokes in real time through a standalone stealer and a malicious browser extension.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware delivered by a ClickFix loader using likely AI-generated obfuscation to hinder static analysis.
Named malware/campaign referenced as prior public reporting that led investigators to uncover SpectrePaste; the article is not primarily about DeepLoad itself.
Fileless malware delivered through ClickFix-style user-executed commands, likely leveraging trusted system tools to avoid traditional defenses.
A malware family delivered via ClickFix campaigns on Windows systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.