BabaDeda Loader is a malware loader first documented by Morphisec in November 2021. It uses ClickFix social engineering to deliver payloads like information stealers and RATs. The loader profiles hosts, avoids Russian/Belarusian systems, and performs security product checks before injecting payloads into trusted Windows processes.