DeepLoad Malware Uses ClickFix and WMI Persistence to Steal Browser Credentials

2026-03-30T19:24:14Z25d92dc127717aa1739f2b263474f71551fdd2569544098531f375cebb68d1b7
AI‑assisted obfuscationCVE-2025-53521CVE-2026-3055Citrix NetScalerClaude extensionClickFixDarkSwordDeepLoadF5 BIG-IPLangChainLangGraphOpen VSXPyPITA446TeamPCPVS Code extensions supply chain','WebRTC skimmer','payment skimsWMI persistencecredential theftiOS exploit kitmalwareprocess injectionsecrets exposuresupply chaintelnyxzero-click XSS

What happened

This feed summarizes multiple high-impact security developments (Mar 26–30, 2026): a newly observed loader named DeepLoad uses ClickFix social‑engineering, AI-assisted obfuscation, WMI persistence and process injection to steal browser credentials; Citrix NetScaler (CVE-2026-3055) is under active reconnaissance; CISA added F5 BIG‑IP APM RCE (CVE-2025-53521) to its KEV list after exploitation; and a range of supply‑chain and platform attacks were disclosed — TeamPCP pushed malicious telnyx releases to PyPI, TA446 deployed the DarkSword iOS exploit kit, Open VSX had a pre‑publish bypass, Anthrop

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
25d92dc127717aa1739f2b263474f71551fdd2569544098531f375cebb68d1b7
Enrichment time
2026-03-30T19:24:14Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.