Home Active WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords
ActiveCybersecurity

WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords

Share
wordlistloader-delivers-amatera-via-clickfix,-synkloader-phishes-windows-passwords
WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords
Share

Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that’s used to deliver next-stage payloads and likely sell access to ransomware groups.

According to findings from Gen Digital, WordlistLoader is being used to deliver Amatera Stealer (aka ACR Stealer or AcridRain Stealer) via ClearFake campaigns, which employ the ClickFix (aka FakeCaptcha) technique to dupe victims into running malicious commands under the pretext of completing CAPTCHA verification checks.

“Once the visitor clicks on the ‘I’m not a robot’ checkbox, they’re walked through the well-known ClickFix flow, where a malicious command is copied into their clipboard and the victim is instructed to paste it into the Windows Run dialog and execute it, leading to the download of WordlistLoader that ultimately results in the execution of Amatera,” security researcher Vojtěch Krejsa said.

The ClickFix prompts are displayed on real websites that have been compromised with malicious JavaScript that’s injected in the form of a Base64-encoded blob. The blob, for its part, fetches another JavaScript from a smart contract stored on the blockchain, an approach known as EtherHiding, and dynamically executes the retrieved code. Some of the compromised websites serving ClickFix prompts are below –

  • abogadosrosarinos[.]com
  • aptisweb[.]com
  • avene-hebergement[.]com
  • https-xhamster[.]com
  • www.caesarjaco.co[.]id
  • skybap[.]shop

In recent months, ClearFake campaigns have been revamped to use “cdn.jsdelivr[.]net” to host the threat actor’s malicious JavaScript, highlighting the abuse of a legitimate Content Delivery Network (CDN) to stage rogue payloads.

“Although the CDN is meant for hosting JavaScript, the threat actors are actually using it to host their malicious PowerShell script,” Expel noted earlier this January. “While jsDelivr appears to be taking down the actor’s malicious repositories fairly quickly, the first stage’s use of EtherHiding allows them to easily swap out burned URLs for fresh working ones.”

The ClickFix command uses “conhost” to launch a hidden “cmd.exe” process, then map a remote WebDAV share using pushd, and finally launch the loader via “rundll32.exe.” It’s worth noting this WebDAV-based approach overlaps with a similar campaign recently highlighted by Microsoft.

In this campaign, a ClickFix prompt instructs the target to run a command that launches “cmd.exe,” which subsequently invokes “rundll32.exe” to load a DLL from a remote WebDAV share accessed over HTTPS. Three different versions of the command have been recorded –

  • Direct rundll32 invocation
  • pushd-Mounted WebDAV Share followed by rundll32.exe invocation
  • Headless and obfuscated pushd execution followed by rundll32.exe invocation (which matches the WordlistLoader infection chain)

“In the more advanced variant, threat actors further enhance stealth by launching commands through conhost.exe –headless, suppressing visible console windows, and employing environment variable obfuscation with delayed variable expansion to conceal critical execution components such as pushd, rundll32, and the remote host name,” Microsoft said.

“Combined with minimized or headless execution, these techniques reduce user visibility, complicate static analysis and detection, and enable the infection chain to execute with minimal indication to the victim.”

The primary difference is that the Python-based loaders observed by Microsoft between late April 2026 and mid-June 2026 in connection with the ACR Stealer intrusion chain have been replaced by WordlistLoader. ACR Stealer has also been propagated via ClickFix prompts that trigger a command spawning MSHTA to retrieve and execute remote HTA content from a threat actor-controlled domain.

This leads to the execution of a VBScript loader that decodes and runs PowerShell designed to fetch a JPEG image from an image-hosting service and extract it from the stealer payload in memory to minimize on-disk artifacts and complicate detection and analysis.

“The primary purpose of WordlistLoader, an intermediate stage in the Amatera infection chain, is to reconstruct a shellcode that serves as the entry point for subsequent stages,” Gen Digital said. At the same time, it employs a hardware-breakpoint-based method to bypass Event Tracing for Windows (ETW) and avoid leaving traces of malicious activity.

WordlistLoader gets its name from the fact that the shellcode is stored in encoded form as a sequence of plain English words, with each word representing one byte. Gen said it also identified a variant that replaces the wordlist with an array of 16-byte UUID-encoded chunks.

The shellcode ultimately makes use of a reflective loader responsible for unpacking and loading Amatera. The same reflective loader was observed in late April 2026 in connection with another ClickFix campaign delivering Amatera 4.3.3-alpha1.

The latest version of the stealer comes with updated static obfuscation, hardened syscall invocation through the WoW64 transition, dynamically generated x64 indirect-syscall trampolines invoked through Heaven’s Gate, and a redesigned application-bound encryption (ABE) bypass that appears to be directly inspired by Remus Stealer

SynkLoader Pushed via Microsoft Teams Phishing

The development comes as SynkLoader has been distributed via a Microsoft Teams phishing campaign to siphon a victim’s system login credentials by serving a fake lock screen. The activity was detected by Expel in mid-August 2025.

“Someone using a @.onmicrosoft.com email (Microsoft 365’s default email domain for companies) reached out to the target using the name IT Service Desk (),” Expel security researcher Marcus Hutchins said.

“The IT service desk convinced the user to download and install an MSI installer from a Microsoft Azure file storage endpoint (https://filereserve.blob.core.windows[.]net/vgnghuyk/331/331.msi), which gave the file the appearance of having come from Microsoft.”

The MSI installer presents itself as a PowerShell Cleaner, which, when run, extracts a ZIP archive and a PowerShell script, the latter of which is automatically run in memory. The script is used to extract the contents of the archive and launch from it a Python-based loader that chooses one of three hard-coded command-and-control (C2) domains and checks in with the server at random, while sleeping for 90 to 120 seconds between requests.

The loader then decrypts and executes the responses from the server. At least seven different modules have been identified –

  • System Profiler, a C# DLL to collect data about the target system.
  • Persistence Module, a native DLL to create a randomly named scheduled task that launches SynkLoader every time the victim logs into the system and daily at 10 a.m.
  • PhishLocker, a DLL to serve a fake Windows lock screen to capture the user’s login password
  • TrafficRedirector, a backconnect or reverse proxy that allows the attacker to reach the local network services or route internet traffic through the infected machine
  • Interactive Shell, a remote access trojan (RAT) module to execute PowerShell commands and transmit the result
  • StreamMaster, a Virtual Network Computing (VNC) module to stream the victim’s desktop and enable remote mouse and keyboard control
  • Status Checker, a Python script to report back the status of which modules are currently running on the system

It’s not clear what the end goals of the operator are, but it’s suspected that the toolkit may be part of a ransomware group or an initial access broker.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Share
Related Articles

⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More

Ravie LakshmananAug 24, 2026Cybersecurity / Hacking A package gets installed. A login...

US Cancels Military Drill With South Korea After Citing Iran War Constraints, Seoul Says

The United States axed a military exercise with South Korea scheduled for...

Norway Pledges $9 Billion to Ukraine for Next Year

Norway has pledged 85 billion Norwegian Kroner ($9.1 billion) to Ukraine, as...

Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt

The Hacker NewsAug 24, 2026AI Security / Webinar If your developers are...