AI/ML, Malware

AI powers clandestine DeepLoad credential-stealing campaign

AI hacker holding a glowing red chip symbolizing artificial intelligence in cybercrime, darkweb, and digital technology threat for cybersecurity and malware protection.

Enterprise business IT environments have been subjected to the DeepLoad credential-stealing malware campaign that ensured stealth via AI abuse and ClickFix attack techniques, according to CyberScoop.

Malicious browser prompts or error pages have been leveraged by attackers to lure targets into executing a command, which runs a loader with a suspected AI-assisted obfuscation layer that evaded various security tools, a report from ReliaQuest revealed. Injection of DeepLoad enabled real-time keylogging, with backups allowing persistence even after the initial loader is thwarted.

"In the incidents we investigated, the loader spread to connected USB drives, which means the initial host is unlikely to be the only impacted system. Even after cleanup, a hidden persistence mechanism not addressed by standard remediation workflows re-executed the attack three days later," said researchers. With AI expected to be increasingly exploited to circumvent static analysis monitoring, organizations' network defenders have been urged to focus on behavioral runtime detection.

An In-Depth Guide to AI

Get essential knowledge and practical strategies to use AI to better your security program.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

Related Terms

Adware

You can skip this ad in 5 seconds