Enterprise business IT environments have been subjected to the DeepLoad credential-stealing malware campaign that ensured stealth via AI abuse and ClickFix attack techniques, according to CyberScoop.Malicious browser prompts or error pages have been leveraged by attackers to lure targets into executing a command, which runs a loader with a suspected AI-assisted obfuscation layer that evaded various security tools, a report from ReliaQuest revealed. Injection of DeepLoad enabled real-time keylogging, with backups allowing persistence even after the initial loader is thwarted."In the incidents we investigated, the loader spread to connected USB drives, which means the initial host is unlikely to be the only impacted system. Even after cleanup, a hidden persistence mechanism not addressed by standard remediation workflows re-executed the attack three days later," said researchers. With AI expected to be increasingly exploited to circumvent static analysis monitoring, organizations' network defenders have been urged to focus on behavioral runtime detection.
AI/ML, Malware
AI powers clandestine DeepLoad credential-stealing campaign

(Adobe Stock)
An In-Depth Guide to AI
Get essential knowledge and practical strategies to use AI to better your security program.
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
Related Terms
AdwareYou can skip this ad in 5 seconds



