Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Trump’s Arctic saber-rattling boosts Iceland’s pro-EU campaign – POLITICO

    August 25, 2026

    US affordability tracker: the data that could decide the 2026 midterms

    August 25, 2026

    After years with an Apple Watch, a Pebble Time 2 ‘downgrade’ was exactly what I needed

    August 25, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Trump’s Arctic saber-rattling boosts Iceland’s pro-EU campaign – POLITICO
    • US affordability tracker: the data that could decide the 2026 midterms
    • After years with an Apple Watch, a Pebble Time 2 ‘downgrade’ was exactly what I needed
    • Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts
    • BNB Chain Activates Pasteur Hard Fork on BSC
    • Israel’s Netanyahu claims Iran tried to kill one of his sons | US-Israel war on Iran News
    • Greece seeks to cash in on Odyssey ‘hype’ – POLITICO
    • Trump Administration Aims to Revoke Visas of Foreign Citizens Applying for Asylum
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, August 25
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Foul Language: WordlistLoader Disguises Malware as Ordinary Text

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 25, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A newly discovered malware loader uses lists of ordinary English words to conceal and reconstruct malicious code, helping a rapidly growing infostealer evade detection before infecting victims.

    Researchers from Gen Threat Labs recently discovered WordlistLoader, a loader used to infect victims with the Amatera infostealer. As a loader, it exists between the initial infection and the final payload. Loaders can be used for a variety of purposes, such as getting deeper into a victim’s machine, evading defenses, downloading and decrypting later stage malware, or launching other necessary programs.

    WordlistLoader’s job is to prepare the environment, evade security controls, reconstruct the next-stage payload, and then hand execution off to the infostealer. “Amatera has been actively developed over the past few months and has gradually become one of the most prevalent infostealers in our user base,” Gen Threat researcher Vojtěch Krejsa wrote in the report.

    Related:DROP Platform Lets Californians Reduce Digital Footprint

    Amatera Stealer (as it’s usually referred to) has been in the wild for a little over a year and has become a popular malware-as-a-service strain. Proofpoint researchers said last June that the stealer is based on the ACR Stealer and is capable of sweeping up data for software wallets, cryptocurrency wallets, credentials, browser data, and message history.

    Like the campaign Proofpoint disclosed a year ago, WordlistLoader is distributed via ClearFake campaigns seemingly targeting Windows machines. ClearFake is a threat cluster that delivers infections primarily via ClickFix-style attacks.

    How WordlistLoader Uses Plain English to Rebuild Malware

    WordlistLoader includes four key functions, according to the Gen report. The primary one is that it “reconstructs shellcode that serves as the entry point for subsequent stages.” WordlistLoader includes a series of plain English words that looks innocuous but can be translated back into executable code prior to running it. Its primary job is to reconstruct hidden malicious code that serves as the entry point for later stages of the infection chain.

    “The mapping from English words to byte values is defined by a build-specific wordlist of 256 distinct words: the word at index 0 decodes to 0x00, the word at index 144 to 0x90, and so on,” Krejsa wrote. “Both the wordlist and the encoded sequence are stored as arrays of pointers, so the loader matches addresses rather than the strings themselves. Rebuilding the shellcode thus comes down to iterating over the word sequence, looking up each word in the list, and writing the index of the matching entry into the output buffer.”

    Related:EU Financial Institutions Leak Data Through Cookie Trackers

    WordlistLoader also unhooks loaded modules; many security products include “hooks” that they insert into various operating system functions as a monitoring tool. Its third feature includes a bypass for Event Tracing for Windows, a built-in Microsoft logging function that assists security tools with observing system activity. Lastly, the malware includes various anti-emulation and anti-analysis tricks to further help with evasion.

    Combatting ClearFake, ClickFix, and Amatera

    The ClearFake cluster is known for compromising legitimate websites and then planting fake CAPTCHA lures that use ClickFix-style social engineering to trick users into executing malicious commands.

    Selena Larson, principal threat researcher at Proofpoint, tells Dark Reading that ClickFix-style attacks have become a popular part of the threat actor’s toolkit. The cybersecurity vendor first included it in its own ZenGuide awareness training in 2024.

    “If organizations aren’t already incorporating ClickFix into their security training, they certainly should be. Based on conversations with various organizations and security teams, the majority are aware of it,” she says. “ClickFix and related techniques are among the most popular methods for delivery used by many different threat actors both in email and web inject initial access.”

    Related:Inconsistent Privacy Labels Don’t Tell Users What They Are Getting

    Larson says, since 2025, Amatera has been used by multiple advanced cybercrime actors. Both she and Gen note that the malware is under continuous development, adding a number of improvements generally involving stealth.

    “Stealers are increasingly popular, but the landscape is shifting rapidly,” she says. “Stealers can become less effective as detection and awareness improve, especially if they aren’t regularly maintained to evade defenses. Also, law enforcement targeting popular malware like StealC, Rhadamanthys, and Lumma Stealer have forced threat actors to go elsewhere, growing the popularity of other information stealers.”

    Disguises Foul language Malware ordinary Text WordlistLoader
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts

    Hired for One Job, Judged on Another: The CISO’s Real Problem

    Hackers target WordPress sites in miniOrange auth bypass attacks

    Unpatched Calix flaw lets hackers bypass NAT to expose internal devices

    Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning

    The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Trump’s Arctic saber-rattling boosts Iceland’s pro-EU campaign – POLITICO

    August 25, 2026

    US affordability tracker: the data that could decide the 2026 midterms

    August 25, 2026

    After years with an Apple Watch, a Pebble Time 2 ‘downgrade’ was exactly what I needed

    August 25, 2026

    Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts

    August 25, 2026
    Latest Posts

    The Doctor and His Diary: What Fauci’s Innermost Musings Reveal

    July 29, 2026

    Iran Considered Retaliatory Strike on Ukrainian Seaport

    July 29, 2026

    The French presidential candidate who wants to blow up the Franco-German engine – POLITICO

    July 29, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Trump’s Arctic saber-rattling boosts Iceland’s pro-EU campaign – POLITICO

    August 25, 2026

    US affordability tracker: the data that could decide the 2026 midterms

    August 25, 2026

    After years with an Apple Watch, a Pebble Time 2 ‘downgrade’ was exactly what I needed

    August 25, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.