HomeCyber BalkansHackers Disguise Malware in Simple Words to Infect Windows Users with Amatera...

Hackers Disguise Malware in Simple Words to Infect Windows Users with Amatera Stealer

Published on

spot_img

Threat Actors Target Windows Systems with ClearFake Campaigns Using Advanced Loader

In a sophisticated development within the landscape of cybercrime, threat actors associated with ongoing ClearFake campaigns have begun employing a new loader known as WordlistLoader to facilitate the delivery of the Amatera Stealer to various Windows systems. This recent move marks an evolution in the tactics used by these cybercriminals, aiming to further evade detection and enhance their capabilities in stealing sensitive information.

The WordlistLoader adopts a distinctive method for concealing executable shellcode, representing it as seemingly simple sequences of English words. This strategy enables the malware to effectively bypass static analysis inspections that are commonly employed by cybersecurity tools. Once activated, the loader reconstructs and initiates the final malicious payload directly in memory, exploiting inherent vulnerabilities in the system.

Previously, organizations such as Microsoft have documented various techniques utilized by ACR Stealer operators—including fake verification prompts and the use of Python loaders. This holistic approach often targeted the theft of critical data such as browser credentials, authentication tokens, and sensitive documents belonging to enterprises. The evolving techniques solidify the understanding that these criminals are increasingly adept at leveraging technology to achieve nefarious objectives.

The infection process initiates when malicious actors compromise legitimate websites, subsequently injecting JavaScript into these sites. This injected script overlays the authentic page with a deceptive CAPTCHA prompt, misleading users into believing they are engaging with a legitimate verification process. Visitors are then prompted to click on an "I’m not a robot" checkbox. However, rather than conducting any genuine verification, this fake interaction triggers a ClickFix workflow.

Victims are further manipulated with instructions to access the Windows Run dialog, where they paste a command stored in their clipboard from the compromised site. This command utilizes conhost to launch a hidden Command Prompt process, mapping a remote WebDAV share through a pushd command, thereby invoking rundll32.exe to execute a run export from a remote DLL.

The campaign adopts a familiar WebDAV-and-ClickFix method, which is similar to the spike in ACR Stealer activities linked to Microsoft’s findings between late April and mid-June of 2026. Notably, WordlistLoader replaces the Python-based intermediate loaders that were common in the earlier phases of these intrusions, indicating a shift towards more innovative and less detectable techniques.

Key to the operation of WordlistLoader is its unique payload encoding methodology. Instead of utilizing standard forms of encrypted shellcode or packed binaries, the loader encodes each byte of shellcode using a specific dictionary of 256 English words. This unconventional approach allows the malware to masquerade as innocuous text, making it far less suspicious during static analysis.

Furthermore, researchers have identified a variant of the loader that employs UUID strings to encode shellcode, converting each UUID into 16 bytes through a process known as UuidFromStringA. Despite this modification, the overall execution flow of the loader remains largely unchanged, indicating a deliberate evolution in tactics aimed at reducing detection.

Before transferring execution to the reconstructed shellcode, WordlistLoader executes several precautionary measures, including a named-event single-instance check and attempts to eliminate hooks from any loaded modules. In addition, the loader has the capability to disable Windows telemetry through a bypass involving Event Tracing for Windows. This multifaceted approach emphasizes the increasing sophistication of malware development.

The loader meticulously enumerates loaded modules and cross-compares the function prologues within memory against clean copies stored on disk. When discrepancies indicative of user-mode hooks are detected, the loader restores original bytes, significantly enhancing its stealth. It employs hardware breakpoints on key functions like ntdll!NtTraceEvent and utilizes a vectored exception handler to obscure its operations from detection.

The decoded shellcode is further equipped with an extensive anti-emulation routine, which prevents automated analysis. The subsequent payload, Amatera 4.3.3-alpha1, features heightened static obfuscation with techniques such as control-flow flattening and individualized API-hash resolvers, complicating efforts at reverse engineering and signature development.

Noteworthy is Amatera’s refined Application-Bound Encryption bypass. Through this capability, the malware actively searches for protected v20_master_key material within the memory of Chromium browsers. It can then inject code into the browser process to decrypt such material, operating within the context where Windows’ CryptProtectMemory protections can be circumvented. This creates significant vulnerabilities, putting saved passwords, cookies, and session data at heightened risk.

As the threat landscape continues to evolve, it remains crucial for both organizations and individuals to remain vigilant. The methods employed by these threat actors underline the need for robust security measures that adapt to counter sophisticated techniques like those seen in the ClearFake campaigns.


Indicators of Compromise (IOCs):
The following domains have been reported as associated with the ongoing campaigns:

  • abogadosrosarinos[.]com
  • aptisweb[.]com
  • avene-hebergement[.]com
  • https-xhamster[.]com
  • caesarjaco[.]co[.]id
  • skybap[.]shop

Note: Domains are intentionally defanged to mitigate unintended resolution. For actionable intelligence, it is advised to use this data in controlled threat intelligence environments. Always exercise caution when navigating this evolving threat landscape.

Source link

Latest articles

Shadow AI: The New Shadow IT and the Importance of Policy as the Starting Point

The Evolving Challenge of Shadow AI: A Need for Enhanced Visibility and Management In the...

Webinar: Beyond the Hype

Transformative Forces: The Impact of AI on Cybersecurity In recent years, artificial intelligence (AI) has...

US Sanctions Mabna Institute Hackers for Iranian Cyber Attacks

Title: US Expands Sanctions Against Iran in New Cybersecurity Initiative In a sweeping expansion of...

More like this

Shadow AI: The New Shadow IT and the Importance of Policy as the Starting Point

The Evolving Challenge of Shadow AI: A Need for Enhanced Visibility and Management In the...

Webinar: Beyond the Hype

Transformative Forces: The Impact of AI on Cybersecurity In recent years, artificial intelligence (AI) has...