New WordlistLoader Hides Malicious Shellcode in English Words to Deploy Amatera Stealer
ID: ddd604db-b895-548d-a3b7-3be0c44bfd69
STIX ID: report--ddd604db-b895-548d-a3b7-3be0c44bfd69
Feed Name: Cyber Press
Gen Threat Labs describes WordlistLoader, a new intermediate malware loader used in ClearFake campaigns to deliver the Amatera stealer via compromised websites presenting fake CAPTCHA prompts (ClickFix). The loader enforces single-instance execution, removes security-product hooks by restoring in-memory exports, bypasses ETW, and reconstructs shellcode encoded as English words or UUIDs to evade static detection; the shellcode includes emulator-frustrating delays and a reflective loader to unpack Amatera. The report includes example compromised domains and highlights the use of WebDAV delivery and social-engineering instructions that trick victims into running a malicious rundll32 command.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
