← Back to Feed

Foul Language: WordlistLoader Disguises Malware as Ordinary Text

August 24, 2026 · Dark Reading · Severity: HIGH

ClickFix-style threat campaigns are using a new trick to evade detection and deliver Amatera, an increasingly prevalent infostealer.

Key Takeaways

  • ClickFix campaigns now use WordlistLoader to disguise Amatera infostealer as plain text files.
  • This technique evades detection by hiding malicious code within seemingly harmless wordlist data.
  • Amatera's rise as a prevalent infostealer highlights evolving tactics in credential theft campaigns.
☕ Buy a Coffee