WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords
Two new malware families, WordlistLoader and SynkLoader, are being used to deliver the Amatera Stealer via ClickFix phishing campaigns. WordlistLoader reconstructs shellcode for Amatera, utilizing techniques to evade detection and analysis, including hardware-breakpoint bypass and static obfuscation. SynkLoader, distributed through a Microsoft Teams phishing campaign, steals login credentials by presenting a fake lock screen and leveraging a PowerShell loader to install various modules, including a remote access trojan and a VNC module. Both campaigns are linked to potential ransomware activity.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
