Close Menu
NCIJ Network NCIJ Network
    What's Hot

    ToxicPanda Banking Trojan Matures Into Enterprise Threat

    August 24, 2026

    Bitcoin Price Returns To $80,000 For First Time In 100 Days

    August 24, 2026

    A ghostly ribbon of stars reveals hidden dark matter

    August 24, 2026
    Facebook X (Twitter) Instagram
    Trending
    • ToxicPanda Banking Trojan Matures Into Enterprise Threat
    • Bitcoin Price Returns To $80,000 For First Time In 100 Days
    • A ghostly ribbon of stars reveals hidden dark matter
    • Antarctic krill fishery closes months early amid increasing fishing pressure
    • Aker Solutions, Microsoft partner to fast-track global CCS, carbon removal pipeline
    • Why Washington Can’t Get Over Humiliation in Iran and Afghanistan
    • Kidnappers release video showing hundreds abducted from Nigerian mosque | Elections News
    • Norway’s King Harald V’s health has worsened, palace says
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, August 24
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 24, 2026 Cybersecurity No Comments6 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that’s used to deliver next-stage payloads and likely sell access to ransomware groups.

    According to findings from Gen Digital, WordlistLoader is being used to deliver Amatera Stealer (aka ACR Stealer or AcridRain Stealer) via ClearFake campaigns, which employ the ClickFix (aka FakeCaptcha) technique to dupe victims into running malicious commands under the pretext of completing CAPTCHA verification checks.

    “Once the visitor clicks on the ‘I’m not a robot’ checkbox, they’re walked through the well-known ClickFix flow, where a malicious command is copied into their clipboard and the victim is instructed to paste it into the Windows Run dialog and execute it, leading to the download of WordlistLoader that ultimately results in the execution of Amatera,” security researcher Vojtěch Krejsa said.

    The ClickFix prompts are displayed on real websites that have been compromised with malicious JavaScript that’s injected in the form of a Base64-encoded blob. The blob, for its part, fetches another JavaScript from a smart contract stored on the blockchain, an approach known as EtherHiding, and dynamically executes the retrieved code. Some of the compromised websites serving ClickFix prompts are below –

    • abogadosrosarinos[.]com
    • aptisweb[.]com
    • avene-hebergement[.]com
    • https-xhamster[.]com
    • www.caesarjaco.co[.]id
    • skybap[.]shop

    In recent months, ClearFake campaigns have been revamped to use “cdn.jsdelivr[.]net” to host the threat actor’s malicious JavaScript, highlighting the abuse of a legitimate Content Delivery Network (CDN) to stage rogue payloads.

    Cybersecurity

    “Although the CDN is meant for hosting JavaScript, the threat actors are actually using it to host their malicious PowerShell script,” Expel noted earlier this January. “While jsDelivr appears to be taking down the actor’s malicious repositories fairly quickly, the first stage’s use of EtherHiding allows them to easily swap out burned URLs for fresh working ones.”

    The ClickFix command uses “conhost” to launch a hidden “cmd.exe” process, then map a remote WebDAV share using pushd, and finally launch the loader via “rundll32.exe.” It’s worth noting this WebDAV-based approach overlaps with a similar campaign recently highlighted by Microsoft.

    In this campaign, a ClickFix prompt instructs the target to run a command that launches “cmd.exe,” which subsequently invokes “rundll32.exe” to load a DLL from a remote WebDAV share accessed over HTTPS. Three different versions of the command have been recorded –

    • Direct rundll32 invocation
    • pushd-Mounted WebDAV Share followed by rundll32.exe invocation
    • Headless and obfuscated pushd execution followed by rundll32.exe invocation (which matches the WordlistLoader infection chain)

    “In the more advanced variant, threat actors further enhance stealth by launching commands through conhost.exe –headless, suppressing visible console windows, and employing environment variable obfuscation with delayed variable expansion to conceal critical execution components such as pushd, rundll32, and the remote host name,” Microsoft said.

    “Combined with minimized or headless execution, these techniques reduce user visibility, complicate static analysis and detection, and enable the infection chain to execute with minimal indication to the victim.”

    The primary difference is that the Python-based loaders observed by Microsoft between late April 2026 and mid-June 2026 in connection with the ACR Stealer intrusion chain have been replaced by WordlistLoader. ACR Stealer has also been propagated via ClickFix prompts that trigger a command spawning MSHTA to retrieve and execute remote HTA content from a threat actor-controlled domain.

    This leads to the execution of a VBScript loader that decodes and runs PowerShell designed to fetch a JPEG image from an image-hosting service and extract it from the stealer payload in memory to minimize on-disk artifacts and complicate detection and analysis.

    “The primary purpose of WordlistLoader, an intermediate stage in the Amatera infection chain, is to reconstruct a shellcode that serves as the entry point for subsequent stages,” Gen Digital said. At the same time, it employs a hardware-breakpoint-based method to bypass Event Tracing for Windows (ETW) and avoid leaving traces of malicious activity.

    WordlistLoader gets its name from the fact that the shellcode is stored in encoded form as a sequence of plain English words, with each word representing one byte. Gen said it also identified a variant that replaces the wordlist with an array of 16-byte UUID-encoded chunks.

    The shellcode ultimately makes use of a reflective loader responsible for unpacking and loading Amatera 4.3.3-alpha1. The same reflective loader was observed in late April 2026 in connection with another ClickFix campaign delivering the stealer malware.

    The latest version of the stealer comes with updated static obfuscation, hardened syscall invocation through the WoW64 transition, dynamically generated x64 indirect-syscall trampolines invoked through Heaven’s Gate, and a redesigned application-bound encryption (ABE) bypass that appears to be directly inspired by Remus Stealer.

    SynkLoader Pushed via Microsoft Teams Phishing

    The development comes as SynkLoader has been distributed via a Microsoft Teams phishing campaign to siphon a victim’s system login credentials by serving a fake lock screen. The activity was detected by Expel in mid-August 2025.

    “Someone using a @.onmicrosoft.com email (Microsoft 365’s default email domain for companies) reached out to the target using the name IT Service Desk (),” Expel security researcher Marcus Hutchins said.

    “The IT service desk convinced the user to download and install an MSI installer from a Microsoft Azure file storage endpoint (https://filereserve.blob.core.windows[.]net/vgnghuyk/331/331.msi), which gave the file the appearance of having come from Microsoft.”

    Cybersecurity

    The MSI installer presents itself as a PowerShell Cleaner, which, when run, extracts a ZIP archive and a PowerShell script, the latter of which is automatically run in memory. The script is used to extract the contents of the archive and launch from it a Python-based loader that chooses one of three hard-coded command-and-control (C2) domains and checks in with the server at random, while sleeping for 90 to 120 seconds between requests.

    The loader then decrypts and executes the responses from the server. At least seven different modules have been identified –

    • System Profiler, a C# DLL to collect data about the target system.
    • Persistence Module, a native DLL to create a randomly named scheduled task that launches SynkLoader every time the victim logs into the system and daily at 10 a.m.
    • PhishLocker, a DLL to serve a fake Windows lock screen to capture the user’s login password
    • TrafficRedirector, a backconnect or reverse proxy that allows the attacker to reach the local network services or route internet traffic through the infected machine
    • Interactive Shell, a remote access trojan (RAT) module to execute PowerShell commands and transmit the result
    • StreamMaster, a Virtual Network Computing (VNC) module to stream the victim’s desktop and enable remote mouse and keyboard control
    • Status Checker, a Python script to report back the status of which modules are currently running on the system

    It’s not clear what the end goals of the operator are, but it’s suspected that the toolkit may be part of a ransomware group or an initial access broker.

    Amatera ClickFix Delivers Passwords Phishes SynkLoader Windows WordlistLoader
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    ToxicPanda Banking Trojan Matures Into Enterprise Threat

    ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More

    ReliaQuest confirms failed data-theft attack after ShinyHunters breach

    Microsoft Teams now lets admins block external bots from meetings

    Microsoft: August updates break printing, PDF export in WPF apps

    Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    ToxicPanda Banking Trojan Matures Into Enterprise Threat

    August 24, 2026

    Bitcoin Price Returns To $80,000 For First Time In 100 Days

    August 24, 2026

    A ghostly ribbon of stars reveals hidden dark matter

    August 24, 2026

    Antarctic krill fishery closes months early amid increasing fishing pressure

    August 24, 2026
    Latest Posts

    The Doctor and His Diary: What Fauci’s Innermost Musings Reveal

    July 29, 2026

    Iran Considered Retaliatory Strike on Ukrainian Seaport

    July 29, 2026

    The French presidential candidate who wants to blow up the Franco-German engine – POLITICO

    July 29, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    ToxicPanda Banking Trojan Matures Into Enterprise Threat

    August 24, 2026

    Bitcoin Price Returns To $80,000 For First Time In 100 Days

    August 24, 2026

    A ghostly ribbon of stars reveals hidden dark matter

    August 24, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.