Skip to content
ClearFake Campaigns Utilize WordlistLoader to Distribute Amatera Infostealer

ClearFake Campaigns Utilize WordlistLoader to Distribute Amatera Infostealer

First seen 21 Aug 2026, 22:19 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •August 22, 2026 at 22:16 UTC
  • •ClearFake uses WordlistLoader to deliver the Amatera infostealer, enhancing evasion tactics.
  • •The malware targets Windows users through compromised websites and fake CAPTCHA prompts.
  • •Organizations should implement specific protections and monitor for unusual process behaviors.

A new malware campaign identified as ClearFake employs a loader named WordlistLoader to deploy the Amatera infostealer, targeting Windows users. This loader reconstructs shellcode from encoded English words, enhancing its evasion capabilities against detection. The Amatera infostealer has advanced features, including Heaven’s Gate for syscall evasion and hijacked thread pools for browser injection. The infection chain begins with compromised websites that display fake CAPTCHA prompts. Security researchers recommend implementing clipboard protections and monitoring for unusual process behavior related to conhost.exe and WebDAV connections. Organizations are advised to isolate affected hosts immediately and conduct memory forensics to identify any injected shellcode. The campaign's sophistication indicates a significant threat to sensitive data stored on infected systems.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 47d ago How this analysis works

Timeline

2026-08-20
ClearFake campaign identified
Researchers discovered the ClearFake campaign using WordlistLoader to deploy Amatera, targeting Windows users.
Cybersecuritynews
2026-08-21
WordlistLoader execution process analyzed
Investigation revealed WordlistLoader's methods, including shellcode decoding and ETW bypass techniques.
Socprime

More articles in this cluster (6)

Following this threat?

Track Amatera in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed