ClickFix and AI Malware: When a single click puts an entire company at risk

Category
Threat Intelligence
Topic
ClickFix & DeepLoad Malware
Audience
Businesses & IT security officers
Reading time
approx. 7 minutes

A new piece of malware called DeepLoad demonstrates just how sophisticated cyberattacks have become, and why traditional antivirus programmes are increasingly failing.

Imagine this: you’re sitting at your work computer, open a website, and suddenly an error message appears. The browser tells you there’s a problem and that you need to run a short command to fix it. You copy the text, paste it in, and have unwittingly triggered an attack that compromises your entire computer and, potentially, the company network.

This is precisely the principle behind ClickFix, an attack method that is currently on the rise. Combined with a new piece of malware called DeepLoad, which uses artificial intelligence for camouflage, a threat has emerged that security researchers classify as ‘imminent’ and particularly dangerous.

What is ClickFix and why does it work so well?

At its core, ClickFix is a form of Social Engineering: the attacker tricks the victim into carrying out the attack themselves. Rather than exploiting complex technical security vulnerabilities, it simply abuses the users’ trust.

The tricky part is that, to users, it looks like a normal troubleshooting process. A deceptively genuine error message in the browser explains an alleged problem and asks users to enter a ‘fix’ into the Windows Command Prompt. What is actually executed, however, is malicious code.

The technique works so well because it capitalises on a fundamental human behaviour: we want to solve problems. An error on the screen makes us anxious, and simple instructions on how to fix it appear to be helpful, not a threat.

What makes DeepLoad so dangerous?

DeepLoad is a new piece of malware that was discovered in real corporate environments at the end of March 2026 by security researchers at ReliaQuest. What sets it apart from many other threats is its combination of several sophisticated techniques:

1

AI-generated camouflage

The malicious code is hidden behind thousands of meaningless lines of code, presumably generated automatically by AI. For traditional antivirus programmes, there is simply too much ‘noise’ to distinguish the real from the fake.

2

Hidden in the lock screen

The Malware embeds itself in a Windows system process that normally manages the lock screen – an area that security tools do not typically monitor.

3

Immediate password theft

At the same time, a fake browser extension is installed that intercepts everything: saved passwords, active logins and session tokens.

4

Self-reactivation after three days

Even if the Malware appears to have been successfully removed, it reactivates itself automatically three days later via a Windows mechanism called WMI, which many IT teams overlook during the clean-up process.

5

Spread via USB

When a USB stick is connected, the Malware copies itself onto it and can thus infect other devices.

Why do conventional security programmes fail?

Traditional antivirus software detects malware by searching for known patterns, known as signatures. DeepLoad, however, does not write any detectable files to the hard drive at all. It runs entirely in RAM, constantly alters its disguise using AI, and hides within legitimate Windows processes.

Security researchers describe it aptly: the Malware is designed to circumvent precisely the defence mechanisms that most companies still rely on.

What specific steps should be taken?

1

For all users

Never copy and execute commands from error messages or unknown websites, no matter how plausible they may seem.

2

For IT teams

Enable PowerShell script block logging and explicitly check and clean up WMI subscriptions on affected systems.

3

If you suspect an issue

Rotate all passwords that have been stored or entered on the affected device, including browser passwords and active sessions.

4

At system level

Treat USB sticks that were connected to affected devices as potentially compromised and review them.

“The most important insight: cyber security is not just a technical issue, but also a human one.”
Mint Secure GmbH

How Mint Secure supports you

User awareness of scams such as ClickFix is at least as important as the best security software. We help you raise cyber security awareness within your organisation so that you are less likely to fall victim to such attacks.

🧠

Security Awareness Training

We train your employees to recognise Social Engineering tricks such as ClickFix before a single click becomes a problem.

🚨

Incident Response

In the event of a suspected incident, we support you in containing, remediating and performing recovery on affected systems.

🛠️

Technical Security Services

We check whether your endpoint protection would even detect memory-resident and AI-disguised Malware such as DeepLoad.

Suspect an infection? We’ll help you quickly and systematically. Get in touch.

Conclusion

DeepLoad is a prime example of a new generation of cyberattacks: technically sophisticated, AI-assisted and designed to remain active even after an apparently successful clean-up.

The combination of human deception (ClickFix) and machine-based obfuscation (AI obfuscation) makes it particularly difficult to detect. Cybersecurity is therefore not just a technical issue, but also a human one.

Mint Secure can help you raise security awareness within your organisation. Talk to us.