New ClickFix Malware Trick Hides Attacks as Plain Text Files
Security researchers have identified a new technique used in ClickFix-style attacks, a method that tricks users into running malicious commands themselves, often by copying and pasting what appears to be a fix for a technical problem. The latest variant, dubbed WordlistLoader, disguises malicious code as harmless-looking text files, making it harder for security software to detect the threat before it executes.
The campaign is being used to deliver Amatera, an infostealer malware that is becoming increasingly common. Infostealers like Amatera are designed to quietly harvest sensitive information such as saved passwords, browser data, and login credentials, which can then be sold or used to access business systems, email accounts, or financial platforms.
ClickFix attacks rely heavily on social engineering rather than technical exploits, meaning they often slip past traditional antivirus defences by convincing the victim to run the malicious code voluntarily. This makes staff awareness a critical line of defence, especially as attackers continue to refine their disguises to look more legitimate and less suspicious.