WordlistLoader is a Windows malware loader used in ClearFake campaigns to deliver the Amatera infostealer, also known as ACR Stealer. It operates as an intermediate execution stage that prepares the host, evades monitoring, reconstructs an encoded payload in memory, and transfers execution to later-stage shellcode and a reflective loader that ultimately loads Amatera.
A defining characteristic of WordlistLoader is its payload encoding scheme. It stores shellcode as sequences of ordinary English words drawn from a build-specific set of 256 unique terms, with each word representing a byte value. During execution, the loader reconstructs the shellcode in memory by resolving each encoded word back to its corresponding byte. Variants have also been observed using UUID-formatted chunks to encode payload data. This design reduces the visibility of raw shellcode in static inspection and complicates analysis.
WordlistLoader incorporates multiple defense-evasion features. Reported behaviors include single-instance checks, restoration or unhooking of loaded module functions to counter user-mode monitoring hooks, bypass of Event Tracing for Windows, and anti-emulation or anti-analysis logic. Observed ETW interference includes a hardware-breakpoint-based technique that redirects tracing-related execution so activity is not logged while avoiding conspicuous failures. Shellcode launched by the loader has also been associated with anti-emulation delay logic before decrypting and executing the next stage.
Distribution has been tied to ClearFake operations that compromise legitimate websites and present fake CAPTCHA or ClickFix prompts. Victims are socially engineered into copying and executing malicious commands through the Windows Run dialog. Those commands abuse native Windows components, including hidden command execution, WebDAV access, and rundll32-based DLL execution, to launch the loader without relying on a software exploit. Some related ClearFake chains have also used EtherHiding to retrieve staging content from blockchain-hosted smart-contract infrastructure.
WordlistLoader is associated with an active infostealer delivery ecosystem centered on Amatera. The malware has been observed in campaigns targeting Windows users and is relevant to financially motivated cybercrime activity focused on credential and browser-data theft through downstream payloads. Reporting also suggests loaders such as WordlistLoader may support broader access-brokering activity, although its directly observed role is payload delivery and execution staging for Amatera.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Researchers from Gen Threat Labs recently discovered WordlistLoader, a loader used to infect victims with the Amatera infostealer.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
the threat actors are actually using it to host their malicious PowerShell script
The ClickFix command uses "conhost" to launch a hidden "cmd.exe" process, then map a remote WebDAV share using pushd, and finally launch the loader via "rundll32.exe."
WordlistLoader includes a series of plain English words that looks innocuous but can be translated back into executable code prior to running it.
Unhooking of all loaded modules... compares the first instruction of each named export with the corresponding instruction in a clean copy read from disk... Whenever a hook is detected, the loader computes the length of the offending jump and restores the original bytes from the clean copy.
WordlistLoader also unhooks loaded modules; many security products include 'hooks' that they insert into various operating system functions as a monitoring tool.
Before it launches the reconstructed payload, it checks whether another copy is already running, attempts to restore altered system-module functions, and interferes with Windows event logging.
Its primary job is to reconstruct hidden malicious code that serves as the entry point for later stages of the infection chain.
Lastly, the malware includes various anti-emulation and anti-analysis tricks to further help with evasion.
33 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A loader distributed in a ClearFake campaign via ClickFix lures using a WebDAV-based approach.
A malware loader that uses a build-specific list of ordinary English words to conceal and reconstruct shellcode, then prepares the environment, evades security controls, unhooks modules, bypasses Event Tracing for Windows, and hands execution to the next-stage payload.
An intermediate loader used in ClickFix/ClearFake infection chains to reconstruct encoded shellcode and launch subsequent stages, ultimately loading Amatera Stealer. It uses shellcode encoded as plain English words or UUID chunks and employs a hardware-breakpoint-based ETW bypass to reduce traces of malicious activity.
A Windows loader used in the ClearFake infection chain that reconstructs shellcode from encoded English words or UUID values, then launches the next-stage payload. It also checks for duplicate execution, attempts to restore altered system-module functions, and interferes with Windows event logging to hinder detection and analysis.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.