AUTO-UPDATED

WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords

Cybersecurity researchers have identified two new malware families, WordlistLoader and SynkLoader, which are being used to deliver malicious payloads and facilitate unauthorized access for potential ransomware operations.

Key Points

  • WordlistLoader delivers the Amatera Stealer by tricking users into executing malicious commands through deceptive "ClickFix" CAPTCHA verification prompts on compromised websites.
  • The WordlistLoader infection chain utilizes hardware breakpoints to bypass Event Tracing for Windows (ETW) and reconstructs shellcode from encoded English word sequences.
  • SynkLoader is distributed via Microsoft Teams phishing campaigns, masquerading as an IT service desk to trick victims into installing a malicious MSI file.
  • Once installed, SynkLoader deploys various modules, including a fake Windows lock screen to capture credentials, a remote access trojan, and a VNC module for desktop control.
  • Threat actors are increasingly abusing legitimate services like jsDelivr CDNs and Azure storage endpoints to host malicious scripts and evade security detection.

Why it Matters

These sophisticated loaders demonstrate a growing trend of using social engineering and legitimate infrastructure to bypass traditional security defenses. By facilitating initial access and credential theft, these tools provide a critical entry point for ransomware groups to compromise enterprise networks.
Internet Published by info@thehackernews.com (The Hacker News)
Read original