# WordlistLoader Delivering Amatera (ACR Stealer) via ClearFake FakeCaptcha Campaigns

> WordlistLoader is a novel loader delivering the Amatera infostealer (rebranded ACR Stealer) through ClearFake campaigns using FakeCaptcha social engineering. The ClickFix infection chain tricks victims into pasting a malicious clipboard command that mounts a remote WebDAV share and executes WordlistLoader via rundll32. WordlistLoader reconstructs shellcode from an English wordlist of 256 words (or UUIDs), unhooks loaded EDR modules, bypasses ETW via hardware breakpoints, and reflectively loads Amatera 4.3.3-alpha1 — an advanced MaaS credential stealer targeting Chromium browser credentials, cryptocurrency wallets, and over 65 browser families with sophisticated evasion including hardened WoW64 syscalls, runtime-generated x64 indirect-syscall trampolines via Heaven's Gate, and a Remus/Lumma-inspired App-Bound Encryption bypass.

- **Published:** 2026-08-18T00:00:00Z
- **Last reviewed:** 2026-08-18T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2367
- **ID:** TL-2026-2367
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 33 (full data via the Threadlinqs MCP server — Purple tier)

## Description

WordlistLoader is a Python-origin intermediate-stage loader first documented by Gen Digital researchers in August 2026, deployed in active ClearFake campaigns using the EtherHiding technique — where malicious JavaScript injected into compromised legitimate websites retrieves second-stage payloads from blockchain smart contracts (BNB Smart Chain, Polygon). Victims visiting compromised sites are presented with a fake CAPTCHA overlay via injected JavaScript; clicking 'I'm not a robot' triggers the ClickFix social engineering flow, copying a malicious command to the clipboard and instructing the victim to paste it into the Windows Run dialog (Win+R, Ctrl+V, Enter).

Three ClickFix command variants have been documented: direct rundll32 invocation from a WebDAV share, pushd-mounted WebDAV share with transparent drive mapping, and a headless variant using 'conhost.exe --headless' to suppress console windows with environment-variable obfuscation via delayed variable expansion masking pushd and rundll32. The commands use @SSL WebDAV syntax over HTTPS to mount remote shares GUID-named directories hosting randomly named DLL files (e.g., gmwmvymdzgqgptwvbslq.dll).

WordlistLoader performs three defense-evasion operations before decoding shellcode: (1) single-instance check via a named event, (2) DLL unhooking by enumerating loaded modules via CreateToolhelp32Snapshot and restoring hook-identified functions from clean disk copies — detecting E9/EB/EA/FF jump opcodes with legacy prefix skipping and x64 syscall stub-aware comparison, and (3) ETW bypass by setting a hardware breakpoint on ntdll!NtTraceEvent with a Vectored Exception Handler that redirects execution to a stub returning STATUS_SUCCESS.

The loader reconstructs shellcode from an encoded wordlist of 256 English words (address-matching rather than string-comparison) or a UUID array decoded via UuidFromStringA. The shellcode includes a NOP sled, anti-emulation stub with time-burning nested loops and self-patching, an XOR decryption stub processing 33-byte records (1-byte key, 32-byte payload), and finally a reflective loader identical to one eSentire documented in April 2026 — suggesting Amatera authorship.

The Amatera stealer (version 4.3.3-alpha1) has evolved significantly from earlier builds. It incorporates control-flow flattening (doubling binary size since v4.1.0-alpha.1), per-resolver API hashing (dozens of multiply-rotate-XOR hash variants making precomputation impractical), splitmix64-round string obfuscation, WoW64 syscall hardening with indirect calls routed through global variables and junk instruction padding (eliminating the detectable fs:0C0h reference), runtime-generated 24-byte x64 indirect-syscall trampolines via Heaven's Gate using double-mapped RW+RX sections, and a redesigned App-Bound Encryption bypass inspired by Remus/Lumma — scanning Chromium memory for the os_crypt_async::Encryptor vftable and hijacking browser thread pools via PoolParty variant 7 (TP_DIRECT remote insertion via NtSetIoCompletion).

The stealer targets 65 Chromium- and Gecko-based browsers (up from 37), 165 browser extension crypto wallets, 137 desktop wallets, messaging apps (Discord, Signal), password managers, and general files matching seed-phrase/crypto key patterns. C2 communication uses ECDH (NIST P-256) key exchange + ChaCha20-Poly1305 AEAD — since v4.0.2 Beta — communicated over HTTPS through NTSockets directly interfacing with \Device\Afd\Endpoint to bypass Winsock hooks, with Cloudflare CDN fronting C2 infrastructure. RecycledGate (FreshyCalls+Hell's Gate) resolves 44 syscall SSNs.

The campaign's infrastructure includes over 100 blockchain-rotated C2 domains on .cc TLD, WebDAV servers on dynamic infrastructure, dead drops on telegra.ph, and over 5,400 compromised websites (primarily WordPress and PrestaShop) serving FakeCaptcha payloads. No named threat actor is attributed to current operations beyond the original developer SheldIO; the ACR Stealer source code was sold in July 2024 leading to the Amatera rebranding.

## MITRE ATT&CK

- T1204 User Execution
- T1059 Command and Scripting Interpreter
- T1106 Native API
- T1218 System Binary Proxy Execution
- T1053 Scheduled Task/Job
- T1685 Disable or Modify Tools
- T1027 Obfuscated Files or Information
- T1055 Process Injection
- T1620 Reflective Code Loading
- T1036 Masquerading
- T1555 Credentials from Password Stores
- T1071 Application Layer Protocol
- T1573 Encrypted Channel
- T1583 Acquire Infrastructure

## Sources

- [WordlistLoader Delivering Amatera via ClearFake Campaigns](https://www.gendigital.com/blog/insights/research/wordlistloader-delivering-amatera-via-clearfake-campaigns)
- [WordlistLoader Delivers Amatera via ClickFix](https://thehackernews.com/2026/08/wordlistloader-delivers-amatera-via.html)
- [Amatera Stealer 4.0.2 Beta: What's New](https://www.esentire.com/blog/amatera-stealer-4-0-2-beta-whats-new-in-this-variant)
- [ACR Stealer: Two Observed Intrusion Chains Amid Increased Threat Activity](https://www.microsoft.com/en-us/security/blog/2026/07/16/acr-stealer-two-observed-intrusion-chains-amid-increased-threat-activity/)
- [Amatera Stealer: Rebranded ACR Stealer With Improved Evasion, Sophistication](https://www.proofpoint.com/us/blog/threat-insight/amatera-stealer-rebranded-acr-stealer-improved-evasion-sophistication)
- [EVALUSION Campaign Delivers Amatera Stealer and NetSupport RAT](https://www.esentire.com/blog/evalusion-campaign-delivers-amatera-stealer-and-netsupport-rat)
- [Threat Actors Deploy WordlistLoader in Latest Amatera Attacks](https://www.broadcom.com/support/security-center/protection-bulletin/threat-actors-deploy-wordlistloader-in-latest-amatera-attacks)
- [ClearFake Campaign: Over 5,400 Hacked Sites Deliver ClickFix Payloads](https://www.bleepingcomputer.com/news/security/clearfake-campaign-over-5400-hacked-sites-deliver-clickfix-payloads/)
- [Foul Language: WordlistLoader Disguises Malware as Ordinary Text](https://www.darkreading.com/data-privacy/wordlistloader-disguises-malware-ordinary-text)
- [WordlistLoader Malware Delivers Amatera via ClearFake](https://securityonline.info/wordlistloader-malware-amatera-stealer/)
- [ACR Stealer Malware Family](https://malpedia.caad.fkie.fraunhofer.de/details/win.acr_stealer)
- [SheldIO Actor Profile](https://mallory.ai/actors/019dc240-3dec-70fa-93f0-961b9db5723d)
- [ClearFake Abusing jsDelivr and Blockchain Dead Drops](https://expel.com/blog/clearfake-abusing-jsdelivr-blockchain-dead-drops/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2367
