Researchers identified WordlistLoader as a new malware loader used in ClearFake campaigns to deliver Amatera Stealer (also tracked as ACR Stealer) through compromised legitimate websites. Victims are shown FakeCaptcha overlays and tricked into running clipboard-delivered commands that abuse conhost, cmd, WebDAV shares, and rundll32 to launch the loader. WordlistLoader then rebuilds shellcode from encoded English words or UUID fragments, unhooks modules, disables ETW logging with a hardware-breakpoint-based bypass, and executes shellcode that decrypts and reflectively loads Amatera. The campaign includes infrastructure such as command-and-control domains, dead-drop URLs, malware hashes, and compromised-site indicators.
The activity also reflects a broader trend of commodity stealers adopting advanced Windows evasion methods more often associated with higher-end malware. Amatera’s newer builds add stronger static obfuscation, stealthier WoW64 syscall invocation, and runtime-built x64 indirect syscall trampolines using Heaven’s Gate, a technique previously documented as a way to bypass user-mode hooks in the WoW64 subsystem. Its updated Chromium Application-Bound Encryption bypass also resembles methods seen in Remus and Lumma, underscoring how infostealer operators are rapidly incorporating sophisticated anti-detection and credential-theft capabilities into large-scale web-injection campaigns.

Pull IOCs and campaign context straight into your stack.
7 events from the most recent confirmed update back to the earliest known activity.
Gen published technical details on WordlistLoader's shellcode reconstruction, unhooking, and ETW bypass, along with Amatera evolution notes and indicators of compromise including hashes, C2 domains, dead-drop URLs, and compromised websites.
Gen Threat Labs identified WordlistLoader as a new loader used in ClearFake campaigns to deliver the Amatera stealer via FakeCaptcha lures on compromised legitimate websites.
Expel observed SynkLoader in a Microsoft Teams phishing campaign in which an actor posing as an IT Service Desk contact used a username@company.onmicrosoft.com account to lure a target into downloading an MSI from Azure Blob Storage. The Python-based loader deployed modules for profiling, persistence, credential theft, proxying, remote shell access, VNC control, and status reporting.
SafeBreach published its Pool Party research, stating it had responsibly disclosed the eight thread-pool injection techniques to Microsoft and affected EDR vendors and released supporting materials for defenders.
Mandiant published research explaining how malware can bypass WOW64 and user-mode inline hooks with Heaven's Gate, and proposed detection by correlating 32-bit and 64-bit syscall hooks.
SafeBreach's research on eight novel Windows thread-pool-based process injection techniques, dubbed Pool Party, was first presented at Black Hat Europe 2023.
According to Gen Threat Labs, Amatera version 4.1.0-alpha.1 introduced control-flow flattening and indirect control-flow obfuscation, and from this version onward used a revamped Chromium Application-Bound Encryption bypass resembling techniques associated with Remus and Lumma.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 48 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
6 references tracked. Mallory keeps watching after this page renders.
darkreading.com
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourcegendigital.com
Open sourcesafebreach.com
Open sourcecloud.google.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.