DeepLoad Malware Uses ClickFix and WMI Persistence to Steal Browser Credentials
2026-03-30T19:24:14Z•25d92dc127717aa1739f2b263474f71551fdd2569544098531f375cebb68d1b7
AI‑assisted obfuscationCVE-2025-53521CVE-2026-3055Citrix NetScalerClaude extensionClickFixDarkSwordDeepLoadF5 BIG-IPLangChainLangGraphOpen VSXPyPITA446TeamPCPVS Code extensions supply chain','WebRTC skimmer','payment skimsWMI persistencecredential theftiOS exploit kitmalwareprocess injectionsecrets exposuresupply chaintelnyxzero-click XSS
What happened
This feed summarizes multiple high-impact security developments (Mar 26–30, 2026): a newly observed loader named DeepLoad uses ClickFix social‑engineering, AI-assisted obfuscation, WMI persistence and process injection to steal browser credentials; Citrix NetScaler (CVE-2026-3055) is under active reconnaissance; CISA added F5 BIG‑IP APM RCE (CVE-2025-53521) to its KEV list after exploitation; and a range of supply‑chain and platform attacks were disclosed — TeamPCP pushed malicious telnyx releases to PyPI, TA446 deployed the DarkSword iOS exploit kit, Open VSX had a pre‑publish bypass, Anthrop
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 25d92dc127717aa1739f2b263474f71551fdd2569544098531f375cebb68d1b7
- Enrichment time
- 2026-03-30T19:24:14Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.