It says it is, but the reality is a little blurry.
DeepLoad exploits ClickFix and WMI persistence to steal credentials, enabling stealth reinfection after three days.