Researchers uncovered two malware families, WordlistLoader and SynkLoader, that are being used to deliver follow-on payloads and may be tied to ransomware access sales. WordlistLoader is linked to ClearFake ClickFix campaigns delivering Amatera Stealer, while SynkLoader was pushed through Microsoft Teams phishing with a fake IT Service Desk and lock screen lure. #WordlistLoader #SynkLoader #AmateraStealer #ClearFake #ClickFix #MicrosoftTeams
Keypoints
- WordlistLoader is used as an intermediate loader to deliver Amatera Stealer.
- ClearFake campaigns abuse ClickFix and compromised websites to trick victims into running commands.
- EtherHiding and jsDelivr are used to stage and swap malicious JavaScript payloads.
- WordlistLoader uses stealth techniques like headless execution, WebDAV, and ETW bypass.
- SynkLoader was spread through Microsoft Teams phishing and fake Microsoft-branded installers.
Read More: https://thehackernews.com/2026/08/wordlistloader-delivers-amatera-via.html