Cybersecurity researchers are uncovering new attack techniques as two malware families, WordlistLoader and SynkLoader, appear to be used as intermediate tools to deploy more dangerous payloads. Their activity is of particular interest, as the access they gain to infected systems could be exploited by ransomware or brokers trading initial access to corporate networks.

ClickFix: The trap that turns the user into an "executor"
In the case of WordlistLoader , Gen Digital researchers found that the malware is a link in the distribution chain of Amatera Stealer , also known as ACR Stealer or AcridRain Stealer. The infection is linked to ClearFake campaigns , which leverage the increasingly common ClickFix technique .
The attack usually starts from a compromised website. The visitor sees a supposed CAPTCHA and is asked to confirm that they are not a bot. However, instead of a simple verification, an instruction appears urging them to copy and execute a Windows command.
The dangerous element is that the action is performed with the user's own participation. Thus, a malicious command can appear as a necessary security step, while in reality it triggers the infection chain.
EtherHiding and abuse of legal infrastructure
Attackers also use the EtherHiding, storing JavaScript snippets in blockchain smart contracts. The malicious code can then be dynamically retrieved, making it difficult to detect and remove.
See also: Over 250 ClickFix Domains Hide Malware Baits
At the same time, there have been cases where the legitimate CDN jsDelivr to host malicious content. Utilizing trusted services is a significant advantage for perpetrators, as their infrastructure can more easily go unnoticed.
The attack chain also uses tools such as cmd.exe, conhost.exe and rundll32.exe, while the use of WebDAV allows for the loading of files from remote resources. In more sophisticated variants, execution is done without a visible window and with obfuscation techniques, reducing the chances of the user noticing anything.

WordlistLoader: The "hidden" intermediate stage
WordlistLoader stands out for the way it stores shellcode. Instead of using an obvious binary format, it encodes the data as a sequence of English words, with each word corresponding to one byte. In another variant, the words have been replaced by 16-byte chunks in UUID format.
The loader's goal is to reconstruct the shellcode and trigger the next stages of the attack. A reflective loader then loads Amatera Stealer into memory, minimizing the traces left on disk.
The newest version of stealer includes additional hiding techniques, advanced methods of executing system calls, and mechanisms that make analysis by security tools more difficult.
See also: DOUBLECUP: ClickFix and hidden PNGs for RAT attacks
SynkLoader: From Microsoft Teams to remote access
Of particular interest is SynkLoader , which has been distributed via phishing in Microsoft Teams . The perpetrators pose as technical support and use addresses that resemble corporate Microsoft 365 accounts.
The victim is convinced to install an MSI file called “PowerShell Cleaner.” The file executes PowerShell code in memory and then activates a Python-based loader, which communicates with C2 infrastructure.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The real threat lies in SynkLoader's capabilities. Available modules can collect system information, create persistence via scheduled tasks, display a fake lock screen to steal passwords, provide an interactive shell, and allow remote control via VNC.

A possible first step towards ransomware
Researchers have not yet definitively attributed the activity to a specific ransomware group, but the combination of credential theft, persistence, remote control access internal network
See also: TWINLOOT: SharePoint and Teams Abused to Steal Credentials
These loaders show how modern attacks don’t have to start with an overtly malicious file. A CAPTCHA, a Teams message, or a seemingly legitimate tool can be the first step in a much larger intrusion. For businesses, educating employees, restricting PowerShell and script interpreters, monitoring unusual WebDAV connections, and implementing multi-factor authentication are now critical defenses.
