Threat reportMalwareTL-2026-2367
WordlistLoader Delivering Amatera (ACR Stealer) via ClearFake FakeCaptcha Campaigns
WordlistLoader Delivering Amatera (ACR Stealer) via (TL-2026-2367), also tracked as ACR Stealer, is a high-severity malware campaign, first published 2026-08-18. It has no confirmed attribution, affects Microsoft Windows, maps to 14 MITRE ATT&CK techniques (T1027, T1036, T1053), and is covered by 9 detection rules and 33 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 14MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 33Indicators of compromise
Key facts for TL-2026-2367
- Threat ID
- TL-2026-2367
- Also known as
- ACR Stealer, AcridRain Stealer, GrMsk Stealer
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- general, cryptocurrency, enterprise
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 33
Malware and tooling in WordlistLoader Delivering Amatera (ACR Stealer) via
Malware and tooling: ACR Stealer, Amatera, ClearFake
How WordlistLoader Delivering Amatera (ACR Stealer) via works
WordlistLoader is a novel loader delivering the Amatera infostealer (rebranded ACR Stealer) through ClearFake campaigns using FakeCaptcha social engineering. The ClickFix infection chain tricks victims into pasting a malicious clipboard command that mounts a remote WebDAV share and executes WordlistLoader via rundll32. WordlistLoader reconstructs shellcode from an English wordlist of 256 words (or UUIDs), unhooks loaded EDR modules, bypasses ETW via hardware breakpoints, and reflectively loads Amatera 4.3.3-alpha1 — an advanced MaaS credential stealer targeting Chromium browser credentials, cryptocurrency wallets, and over 65 browser families with sophisticated evasion including hardened WoW64 syscalls, runtime-generated x64 indirect-syscall trampolines via Heaven's Gate, and a Remus/Lumma-inspired App-Bound Encryption bypass.
WordlistLoader is a Python-origin intermediate-stage loader first documented by Gen Digital researchers in August 2026, deployed in active ClearFake campaigns using the EtherHiding technique — where malicious JavaScript injected into compromised legitimate websites retrieves second-stage payloads from blockchain smart contracts (BNB Smart Chain, Polygon). Victims visiting compromised sites are presented with a fake CAPTCHA overlay via injected JavaScript; clicking 'I'm not a robot' triggers the ClickFix social engineering flow, copying a malicious command to the clipboard and instructing the victim to paste it into the Windows Run dialog (Win+R, Ctrl+V, Enter).
Three ClickFix command variants have been documented: direct rundll32 invocation from a WebDAV share, pushd-mounted WebDAV share with transparent drive mapping, and a headless variant using 'conhost.exe --headless' to suppress console windows with environment-variable obfuscation via delayed variable expansion masking pushd and rundll32. The commands use @SSL WebDAV syntax over HTTPS to mount remote shares GUID-named directories hosting randomly named DLL files (e.g., gmwmvymdzgqgptwvbslq.dll).
WordlistLoader performs three defense-evasion operations before decoding shellcode: (1) single-instance check via a named event, (2) DLL unhooking by enumerating loaded modules via CreateToolhelp32Snapshot and restoring hook-identified functions from clean disk copies — detecting E9/EB/EA/FF jump opcodes with legacy prefix skipping and x64 syscall stub-aware comparison, and (3) ETW bypass by setting a hardware breakpoint on ntdll!NtTraceEvent with a Vectored Exception Handler that redirects execution to a stub returning STATUS_SUCCESS.
The loader reconstructs shellcode from an encoded wordlist of 256 English words (address-matching rather than string-comparison) or a UUID array decoded via UuidFromStringA. The shellcode includes a NOP sled, anti-emulation stub with time-burning nested loops and self-patching, an XOR decryption stub processing 33-byte records (1-byte key, 32-byte payload), and finally a reflective loader identical to one eSentire documented in April 2026 — suggesting Amatera authorship.
The Amatera stealer (version 4.3.3-alpha1) has evolved significantly from earlier builds. It incorporates control-flow flattening (doubling binary size since v4.1.0-alpha.1), per-resolver API hashing (dozens of multiply-rotate-XOR hash variants making precomputation impractical), splitmix64-round string obfuscation, WoW64 syscall hardening with indirect calls routed through global variables and junk instruction padding (eliminating the detectable fs:0C0h reference), runtime-generated 24-byte x64 indirect-syscall trampolines via Heaven's Gate using double-mapped RW+RX sections, and a redesigned App-Bound Encryption bypass inspired by Remus/Lumma — scanning Chromium memory for the os_crypt_async::Encryptor vftable and hijacking browser thread pools via PoolParty variant 7 (TP_DIRECT remote insertion via NtSetIoCompletion).
The stealer targets 65 Chromium- and Gecko-based browsers (up from 37), 165 browser extension crypto wallets, 137 desktop wallets, messaging apps (Discord, Signal), password managers, and general files matching seed-phrase/crypto key patterns. C2 communication uses ECDH (NIST P-256) key exchange + ChaCha20-Poly1305 AEAD — since v4.0.2 Beta — communicated over HTTPS through NTSockets directly interfacing with \Device\Afd\Endpoint to bypass Winsock hooks, with Cloudflare CDN fronting C2 infrastructure. RecycledGate (FreshyCalls+Hell's Gate) resolves 44 syscall SSNs.
The campaign's infrastructure includes over 100 blockchain-rotated C2 domains on .cc TLD, WebDAV servers on dynamic infrastructure, dead drops on telegra.ph, and over 5,400 compromised websites (primarily WordPress and PrestaShop) serving FakeCaptcha payloads. No named threat actor is attributed to current operations beyond the original developer SheldIO; the ACR Stealer source code was sold in July 2024 leading to the Amatera rebranding.
MITRE ATT&CK techniques used in TL-2026-2367
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1055 Process Injection; T1620 Reflective Code Loading
Persistence
Execution
T1059 Command and Scripting Interpreter; T1106 Native API
Command and Control
T1071 Application Layer Protocol; T1573 Encrypted Channel
execution
stealth
T1218 System Binary Proxy Execution
Credential Access
T1555 Credentials from Password Stores
Resource Development
defense-impairment
Affected products and versions in WordlistLoader Delivering Amatera (ACR Stealer) via
- Microsoft — Windows
Vulnerable versions: 7; 8.1; 10; 11; Server 2008; Server 2012; Server 2016; Server 2019; Server 2022 - Google — Chrome
Vulnerable versions: All versions with Chromium App-Bound Encryption - Microsoft — Edge
Vulnerable versions: All Chromium-based versions - Various — Chromium-based browsers (65 families including Brave, Opera, Vivaldi, Perplexity Comet, GhostBrowser, Naver Whale, and others)
Vulnerable versions: All - Various — Gecko-based browsers (Firefox, Zen, Mullvad Browser, LibreWolf, SeaMonkey, and others)
Vulnerable versions: All with stored credentials
Remediation for WordlistLoader Delivering Amatera (ACR Stealer) via
Patches
- No vendor patches applicable — campaign exploits user behavior, not software vulnerabilities
Immediate actions
- Block .cc TLD domains at network perimeter or apply strict HTTP inspection
- Monitor for WebDAV pushd commands with @SSL syntax in process creation logs (conhost --headless, pushd \\server@SSL)
- Enable PowerShell Script Block Logging and Module Logging across all endpoints
- Deploy hunting queries for suspicious rundll32.exe execution loading DLLs from remote WebDAV paths
- Block known IOC hashes and domains at perimeter and endpoint security controls
- Review and restrict outbound SMB/WebDAV connections (TCP 445, 443 WebDAV) from workstations
Workarounds
- Educate users: never paste clipboard content into Run dialog from a web page prompt
- Disable WebDAV client service (WebClient) on workstations where not business-required
- Restrict PowerShell execution policy via GPO to constrained language mode
- Block mshta.exe execution via attack surface reduction rules
- Enforce browser policies disabling automatic execution of downloaded content
Longer-term hardening
- Deploy EDR with behavioral detection rules for DLL unhooking (CreateToolhelp32Snapshot + module restoration), ETW bypass via hardware breakpoints, and Heaven's Gate WoW64 transitions
- Enforce AppLocker or Windows Defender Application Control to restrict rundll32, mshta, msbuild execution from non-system paths
- Implement network segmentation limiting workstation-to-workstation SMB/WebDAV access
- Deploy AMSI in conjunction with PowerShell constrained language mode
- Conduct regular user security awareness training on ClickFix/FakeCaptcha social engineering variants
- Monitor for PoolParty variant thread-pool injection indicators (NtSetIoCompletion on non-system handles)
Timeline of WordlistLoader Delivering Amatera (ACR Stealer) via
- Threat actor SheldIO begins selling GrMsk Stealer precursor to ACR/Amatera as a private MaaS on Russian-language cybercrime forums
- ACR Stealer first marketed as a separate MaaS product by SheldIO on Russian-speaking underground forums, written in C++, targeting Windows 7-10
- ACR Stealer sales suspended; source code reportedly sold via Telegram announcement, leading to subsequent Amatera Stealer rebranding and continued evolution by new operators
- Amatera Stealer rebranded version first surfaces; public MaaS panel scans detected, offering monthly ($199) and yearly ($1,499) subscription plans with Telegram-based customer support
- Proofpoint publishes analysis of Amatera Stealer as rebranded ACR Stealer, documenting MaaS model, NTSockets networking, WoW64 syscalls, and ClearFake distribution via EtherHiding blockchain dead drops
- eSentire TRU documents EVALUSION campaign delivering Amatera Stealer and NetSupport RAT via ClickFix; Amatera uses WoW64 syscalls, targets 165+ crypto wallet extensions; NetSupport license file references cluster name 'EVALUSION' and licensee 'KAKAN'
- Earliest observed Amatera dead drops on telegra[.]publishing platform (Jewel-03-06, Catnap-Skimmed-03-06); BleepingComputer reports over 5,400 compromised WordPress and PrestaShop sites delivering ClearFake ClickFix payloads via BNB Smart Chain EtherHiding
- Amatera 4.0.2 Beta documented by eSentire; major upgrades include ECDH NIST P-256 + ChaCha20-Poly1305 C2 encryption (replacing AES-256-CBC), RecycledGate (FreshyCalls+Hell's Gate) syscall resolution, 44 resolved SSNs, expanded browser targets from 37 to 65, wallet extensions from 132 to 165, desktop wallets from 41 to 137, Discord/Signal harvesting
- Reflective loader first observed in ClickFix campaign delivering Amatera 4.0.2 Beta (per eSentire) — identical loader later used in WordlistLoader campaign, suggesting common Amatera authorship
- Microsoft Defender Experts observe increased ACR Stealer activity beginning, lasting through mid-June 2026; two distinct intrusion chains documented: WebDAV-based ClickFix with Python loaders and blockchain dead-drop C2, and fileless MSHTA-initiated PowerShell with JPEG steganography
- ClearFake smart contract payload zeroed out on BNB Smart Chain; compromised websites remain infected but temporarily stop serving ClickFix prompts — infrastructure can be reactivated with single on-chain transaction
- Additional Amatera dead drops observed (Executing-modules-as-scripts-06-16, Using-Python-as-a-Calculator-06-05); Python-based loaders in ACR Stealer chain active per Microsoft tracking
- Microsoft publishes detailed analysis of ACR Stealer intrusion chains, documenting three ClickFix command variants (direct rundll32, pushd-mounted WebDAV, headless conhost obfuscation), 97+ unique C2 domains with blockchain rotation, and steganographic payload delivery via JPEG images on image-hosting services
- Gen Digital (Vojtěch Krejsa) publishes WordlistLoader analysis documenting Amatera 4.3.3-alpha1 — novel loader with wordlist-to-byte shellcode reconstruction, DLL unhooking, hardware-breakpoint ETW bypass, UUID variant, hardened WoW64 with indirect calls and Heaven's Gate x64 trampolines, Remus/Lumma-inspired ABE bypass via memory scanning and PoolParty variant 7 thread-pool injection; Broadcom/Symantec publishes concurrent protection bulletin
- WordlistLoader/Amatera campaign continues actively; PhishEye research documents 97 unique C2 domains across 113 on-chain rotations on Polygon from March to June 2026; campaign scales with single-transaction domain rotation allowing rapid infrastructure refresh
Sources cited for WordlistLoader Delivering Amatera (ACR Stealer) via
- WordlistLoader Delivering Amatera via ClearFake Campaigns
- WordlistLoader Delivers Amatera via ClickFix
- Amatera Stealer 4.0.2 Beta: What's New
- ACR Stealer: Two Observed Intrusion Chains Amid Increased Threat Activity
- Amatera Stealer: Rebranded ACR Stealer With Improved Evasion, Sophistication
- EVALUSION Campaign Delivers Amatera Stealer and NetSupport RAT
- Threat Actors Deploy WordlistLoader in Latest Amatera Attacks
- ClearFake Campaign: Over 5,400 Hacked Sites Deliver ClickFix Payloads
- Foul Language: WordlistLoader Disguises Malware as Ordinary Text
- WordlistLoader Malware Delivers Amatera via ClearFake
- ACR Stealer Malware Family
- SheldIO Actor Profile
- ClearFake Abusing jsDelivr and Blockchain Dead Drops
Detection coverage for TL-2026-2367
As of 2026-08-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2367 across Splunk SPL, Microsoft KQL and Sigma, covering 33 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.