ZeroHour
Dark Readingpublished ()ingested Alexander Culafi

Foul Language: WordlistLoader Disguises Malware as Ordinary Text

mediumMalware exploited in the wildimportance 50
AI summary · glm-5.3-flash

ClickFix-style campaigns deploy WordlistLoader, which disguises malware as ordinary text, to deliver the increasingly prevalent Amatera infostealer.

Researchers describe WordlistLoader, a new loader that disguises malicious payloads as ordinary text or wordlist files to evade detection. It is being used in ClickFix-style social engineering campaigns to deliver Amatera, an increasingly prevalent infostealer. The obfuscation technique helps the campaign slip past file-type-based inspections.

  • WordlistLoader hides payloads as plain text or wordlists
  • Delivered via ClickFix-style social engineering lures
  • Deploys Amatera infostealer, growing in prevalence
  • Technique evades file-type-based detection
Full article

ClickFix-style threat campaigns are using a new trick to evade detection and deliver Amatera, an increasingly prevalent infostealer.

This source does not provide full text. Read it at darkreading.com.