logo

New WordlistLoader Hides Malicious Shellcode in English Words to Deploy Amatera Stealer

ID: ddd604db-b895-548d-a3b7-3be0c44bfd69

STIX ID: report--ddd604db-b895-548d-a3b7-3be0c44bfd69

Feed Name: Cyber Press

Threat Score
72/100

Date Published: 2026-08-26

Date Updated: 2026-08-26

Author: Varshini

...
...

Gen Threat Labs describes WordlistLoader, a new intermediate malware loader used in ClearFake campaigns to deliver the Amatera stealer via compromised websites presenting fake CAPTCHA prompts (ClickFix). The loader enforces single-instance execution, removes security-product hooks by restoring in-memory exports, bypasses ETW, and reconstructs shellcode encoded as English words or UUIDs to evade static detection; the shellcode includes emulator-frustrating delays and a reflective loader to unpack Amatera. The report includes example compromised domains and highlights the use of WebDAV delivery and social-engineering instructions that trick victims into running a malicious rundll32 command.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.