
New Malware Families WordlistLoader and SynkLoader Discovered Deploying Amatera Stealer
CybersecurityMalwareRansomwareCredentialTheft
Cybersecurity researchers at Gen Digital identified two new malware families, WordlistLoader and SynkLoader, used to deploy next-stage payloads and potentially sell access to ransomware groups. WordlistLoader is actively delivering Amatera Stealer (also known as ACR Stealer or AcridRain Stealer) through ClearFake campaigns, which leverage the ClickFix (or FakeCaptcha) technique. No specific dates, victim counts, or technical indicators such as CVE IDs were disclosed in the findings. The malware families appear designed for credential theft and follow-on exploitation, though exact impacts beyond payload delivery remain unspecified. The report did not detail geographic targeting or affected sectors.