Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New Malware Threats: WordlistLoader and SynkLoader Unveiled

New Malware Threats: WordlistLoader and SynkLoader Unveiled

Posted on August 24, 2026 By CWS

Recent cybersecurity investigations have uncovered two new malware families, WordlistLoader and SynkLoader, which are being leveraged to deploy subsequent malicious payloads and potentially facilitate ransomware activities. As reported by Gen Digital, WordlistLoader is implicated in the distribution of Amatera Stealer through ClearFake campaigns, employing a tactic known as ClickFix to deceive users into executing harmful commands under the guise of CAPTCHA verification.

Understanding the WordlistLoader Threat

WordlistLoader operates by tricking users into copying and pasting malicious commands after clicking on a seemingly harmless ‘I’m not a robot’ checkbox. This process involves the execution of WordlistLoader, which subsequently initiates the Amatera Stealer. According to Vojtěch Krejsa, a security researcher, this threat is presented through compromised websites embedded with malicious JavaScript using Base64 encoding. This script retrieves additional JavaScript via a smart contract on the blockchain, a technique known as EtherHiding.

Compromised websites involved in this scheme include domains such as abogadosrosarinos[.]com and aptisweb[.]com. These sites host ClickFix prompts that are designed to manipulate users into executing commands that facilitate malware installation. The abuse of legitimate Content Delivery Networks (CDNs) like “cdn.jsdelivr[.]net” for hosting malicious scripts showcases an evolving threat landscape.

Advanced Techniques and New Variants

WordlistLoader employs a sophisticated infection chain, utilizing conhost to start a concealed cmd.exe process, mapping remote WebDAV shares, and ultimately launching the loader via rundll32.exe. Microsoft’s recent findings indicate that similar WebDAV-based campaigns have been observed, indicating a broader trend in these attack strategies. These campaigns involve various command versions that complicate detection and analysis by using headless execution and environment variable obfuscation.

Additionally, WordlistLoader’s shellcode is encoded as English words, each representing a byte, which complicates analysis. This malware also features a reflective loader for unpacking Amatera and bypasses detection mechanisms using hardware-breakpoint-based methods.

SynkLoader’s Phishing Tactics

Meanwhile, SynkLoader has been involved in a phishing campaign targeting Microsoft Teams users, aiming to harvest login credentials by displaying a counterfeit lock screen. As identified by Expel in mid-August 2025, attackers posing as IT service desks convinced users to download an MSI installer from a Microsoft Azure endpoint, masquerading as a PowerShell Cleaner.

This installer extracts a ZIP archive and a PowerShell script that executes in memory, launching a Python-based loader. This loader communicates with command-and-control domains, executing server responses with various modules designed for data collection, persistence, and remote access, among others.

These sophisticated methods highlight the persistent threat posed by these malware families and underscore the importance of robust cybersecurity measures to protect against evolving tactics.

As these threats continue to develop, cybersecurity experts emphasize the need for vigilance and proactive defenses to mitigate the risks posed by WordlistLoader, SynkLoader, and similar malware.

The Hacker News Tags:CAPTCHA attacks, ClickFix, Cybersecurity, EtherHiding, Expel, Gen Digital, JavaScript, malware threats, Microsoft Teams phishing, PowerShell, Ransomware, rundll32.exe, SynkLoader, WordlistLoader

Post navigation

Previous Post: New SynkLoader Malware Targets Microsoft Teams Users
Next Post: Broadcom Addresses 91 Security Flaws in Spring Framework

Related Posts

26 Malicious Apps on Apple Store Targeting Crypto Wallets 26 Malicious Apps on Apple Store Targeting Crypto Wallets The Hacker News
CISA Adds 3 D-Link Vulnerabilities to KEV Catalog Amid Active Exploitation Evidence CISA Adds 3 D-Link Vulnerabilities to KEV Catalog Amid Active Exploitation Evidence The Hacker News
JINX-0164 Hits Crypto Firms with Sophisticated MacOS Malware JINX-0164 Hits Crypto Firms with Sophisticated MacOS Malware The Hacker News
Lunex Stealer Exploits AMD Driver for Credential Theft Lunex Stealer Exploits AMD Driver for Credential Theft The Hacker News
StreamRat Android Trojan Exploits Meta Ads for Device Control StreamRat Android Trojan Exploits Meta Ads for Device Control The Hacker News
CHILLYHELL macOS Backdoor and ZynorRAT RAT Threaten macOS, Windows, and Linux Systems CHILLYHELL macOS Backdoor and ZynorRAT RAT Threaten macOS, Windows, and Linux Systems The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • VirusTotal API Keys Allegedly Sold on Dark Web
  • Fortinet Devices Targeted by FortiBleed Attackers
  • Japan Faces Surge in Data Breaches Due to API and Software Vulnerabilities
  • Zammad Flaw Allows Remote Code Execution via Session Leak
  • Hackers Exploit Atlassian Vulnerability Soon After Disclosure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • VirusTotal API Keys Allegedly Sold on Dark Web
  • Fortinet Devices Targeted by FortiBleed Attackers
  • Japan Faces Surge in Data Breaches Due to API and Software Vulnerabilities
  • Zammad Flaw Allows Remote Code Execution via Session Leak
  • Hackers Exploit Atlassian Vulnerability Soon After Disclosure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark