threat-intel Foul Language: WordlistLoader Disguises Malware as Ordinary Text A new malware loader called WordlistLoader is being used to deliver the Amatera infostealer, primarily through ClickFix-style campaigns. WordlistLoader disguises malicious code using lists of ordinary English words, allowing it to evade security controls and deliver the stealer. Amatera, a rapidly growing infostealer,… Dark Reading · 5d ago High malwareloaderinfostealer
threat-intel China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks A China-nexus operation, tracked by Group-IB, dubbed JadeProx, is using a new loader called TriBack Loader to target government, healthcare, and education organizations across Asia and Latin America. The operation levera… The Hacker News · Jul 23, 2026 High CVE-2018-11511CVE-2021-24139CVE-2021-31755CHHOVIloaderspear-phishingvulnerability
threat-intel StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader A new malware family, named SharkLoader, has been identified as part of a broader campaign targeting organizations globally, including diplomatic entities, government organizations, and software development companies. Th… Securelist · Jun 24, 2026 Medium CVE-2021-26855CVE-2023-32315CVE-2024-36401IDTWHKcobalt strikeexploitloader
threat-intel ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures ClickFix campaigns are expanding their malware delivery tactics with new loaders, including BabaDeda Loader, Lorem Ipsum Loader, and Storage Crypter, targeting education and financial organizations. These attacks utilize… The Hacker News · Jun 16, 2026 High RUBYsocial engineeringloaderpayload