logo

Foul Language: WordlistLoader Disguises Malware as Ordinary Text

ID: 795d8c80-070e-561a-92bc-eeca9ed54351

STIX ID: report--795d8c80-070e-561a-92bc-eeca9ed54351

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2026-08-24

Date Updated: 2026-08-25

Author: Alexander Culafi

...
...

Researchers discovered WordlistLoader, a loader that hides and reconstructs shellcode using a build-specific 256-word English wordlist to deliver the Amatera infostealer; it is distributed via ClearFake/ClickFix-style social-engineering campaigns and includes evasion features such as module unhooking, Event Tracing for Windows bypasses, and anti-emulation/analysis techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.