news.mlab.sh
Back to the feed
threat-intel

WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords

High
Image: The Hacker News
Summary

Two new malware families, WordlistLoader and SynkLoader, are being used to deliver the Amatera Stealer via ClickFix phishing campaigns. WordlistLoader reconstructs shellcode for Amatera, utilizing techniques to evade detection and analysis, including hardware-breakpoint bypass and static obfuscation. SynkLoader, distributed through a Microsoft Teams phishing campaign, steals login credentials by presenting a fake lock screen and leveraging a PowerShell loader to install various modules, including a remote access trojan and a VNC module. Both campaigns are linked to potential ransomware activity.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.