Socprime ClearFake Campaigns Utilize WordlistLoader to Distribute Amatera Infostealer
Article Content
- •ClearFake uses WordlistLoader to deliver the Amatera infostealer, enhancing evasion tactics.
- •The malware targets Windows users through compromised websites and fake CAPTCHA prompts.
- •Organizations should implement specific protections and monitor for unusual process behaviors.
A new malware campaign identified as ClearFake employs a loader named WordlistLoader to deploy the Amatera infostealer, targeting Windows users. This loader reconstructs shellcode from encoded English words, enhancing its evasion capabilities against detection. The Amatera infostealer has advanced features, including Heaven’s Gate for syscall evasion and hijacked thread pools for browser injection. The infection chain begins with compromised websites that display fake CAPTCHA prompts. Security researchers recommend implementing clipboard protections and monitoring for unusual process behavior related to conhost.exe and WebDAV connections. Organizations are advised to isolate affected hosts immediately and conduct memory forensics to identify any injected shellcode. The campaign's sophistication indicates a significant threat to sensitive data stored on infected systems.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track Amatera in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Cisco Talos Reports ClickFix Attacks Targeting Cryptocurrency Traders Cisco Talos has identified two ClickFix attack campaigns that exploit trusted services to deceive victims into executing malicious code. The first campaign, active since October 2025, targets cryptocurrency traders with fake security reports, leading them to paste JavaScript into their browsers, which then retrieves…
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…