Cybersecurity researchers have identified two new malware families, WordlistLoader and SynkLoader, which are being used to deliver malicious payloads and facilitate unauthorized access for potential ransomware operations.
Key Points
- WordlistLoader delivers the Amatera Stealer by tricking users into executing malicious commands through deceptive "ClickFix" CAPTCHA verification prompts on compromised websites.
- The WordlistLoader infection chain utilizes hardware breakpoints to bypass Event Tracing for Windows (ETW) and reconstructs shellcode from encoded English word sequences.
- SynkLoader is distributed via Microsoft Teams phishing campaigns, masquerading as an IT service desk to trick victims into installing a malicious MSI file.
- Once installed, SynkLoader deploys various modules, including a fake Windows lock screen to capture credentials, a remote access trojan, and a VNC module for desktop control.
- Threat actors are increasingly abusing legitimate services like jsDelivr CDNs and Azure storage endpoints to host malicious scripts and evade security detection.