← Back to Feed
Foul Language: WordlistLoader Disguises Malware as Ordinary Text
August 24, 2026 · Dark Reading · Severity: HIGH
ClickFix-style threat campaigns are using a new trick to evade detection and deliver Amatera, an increasingly prevalent infostealer.
Key Takeaways
- ClickFix campaigns now use WordlistLoader to disguise Amatera infostealer as plain text files.
- This technique evades detection by hiding malicious code within seemingly harmless wordlist data.
- Amatera's rise as a prevalent infostealer highlights evolving tactics in credential theft campaigns.