New Malware Loaders WordlistLoader and SynkLoader Target Windows Users
Cybersecurity researchers at Gen Digital have identified two new pieces of malware, dubbed WordlistLoader and SynkLoader, that are being used to install further malicious software on infected computers. These tools act as 'loaders' — their job is to quietly deliver more dangerous payloads once a device has been compromised, and access to infected machines may then be sold to other criminal groups, including ransomware operators.
WordlistLoader has been observed delivering Amatera Stealer, an information-stealing malware also known as ACR Stealer or AcridRain Stealer. It is being spread through ClearFake campaigns, which rely on a deceptive technique known as ClickFix (or FakeCaptcha). This method tricks users into believing they are completing a routine security check, such as a CAPTCHA, when in fact they are unknowingly executing malicious commands that install the malware on their system.
SynkLoader, meanwhile, is being used in phishing attacks aimed at stealing Windows passwords. Both threats highlight the growing sophistication of malware distribution tactics, where attackers use fake verification prompts and social engineering to bypass user suspicion rather than relying purely on technical exploits.