logo

WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords

ID: 4fa464b3-a417-5a9c-8527-cfb21a00d011

STIX ID: report--4fa464b3-a417-5a9c-8527-cfb21a00d011

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-08-24

Date Updated: 2026-08-24

Author: [email protected] (The Hacker News)

...
...

Researchers have identified two active malware families—WordlistLoader and SynkLoader—being used to deliver the Amatera (ACR/AcridRain) stealer and to harvest credentials and provide remote access. Distribution leverages ClearFake/ClickFix lures on compromised websites (with EtherHiding and CDN abuse), WebDAV-based DLL loading via rundll32, and a Microsoft Teams phishing campaign that installs an MSI leading to a Python-based loader; SynkLoader includes modules for persistence, fake lock-screen credential capture, reverse proxying, RAT functionality and VNC streaming.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.