-
Researchers found two new malware tools called WordlistLoader and SynkLoader. Both may end up sold to ransomware gangs.
-
WordlistLoader hides inside fake CAPTCHA checks on hacked websites. It quietly installs a data-stealing program called Amatera Stealer.
-
SynkLoader spreads through fake Microsoft Teams messages. It can show a fake lock screen to steal your password.
Cybersecurity researchers have spotted two new malware families. They go by the names WordlistLoader and SynkLoader. Both tools deliver harmful programs onto victims’ computers. Experts believe the people behind them may sell access to ransomware groups.
How WordlistLoader Sneaks Amatera Onto Your Computer
According to Gen Digital, WordlistLoader helps spread a program called Amatera Stealer. Some people also call it ACR Stealer or AcridRain Stealer. The tool travels through ClearFake campaigns. These campaigns use a trick called ClickFix, also known as FakeCaptcha.
Here is how the scam works. A visitor lands on a hacked website. The site shows a fake “I’m not a robot” box. Once clicked, the site walks the visitor through a few steps. A harmful command gets copied to the visitor’s clipboard.
Ukraine’s CERT-UA says Russian-backed Sandworm hackers are using ClickFix and fake CAPTCHA pages to trick Ukrainian government and infrastructure workers into executing malicious PowerShell commands.
The victim then pastes it into the Windows Run box. Running that command downloads WordlistLoader. That, in turn, installs Amatera on the machine, Gen Digital researcher Vojtěch Krejsa explained.
These fake CAPTCHA popups show up on real websites. Hackers plant hidden code on those sites first. The code fetches more instructions from a smart contract stored on the blockchain. Experts call this method EtherHiding. Some affected sites include abogadosrosarinos[.]com, aptisweb[.]com, and avene-hebergement[.]com, among others.
Lately, these campaigns have leaned on a legitimate file-hosting service called jsDelivr. The security firm Expel noted that although the service is meant for regular code, attackers use it to store their harmful scripts instead. Expel also pointed out that the hackers can swap out blocked links for new ones quickly, thanks to EtherHiding.
The ClickFix command hides itself in several ways. It uses one program to quietly open another, then borrows a shared network drive to launch the final loader. Microsoft flagged a similar pattern in a separate campaign.
Microsoft explained that attackers now hide their commands even better. They suppress visible windows and delay how commands appear, making the attack harder to catch.
Earlier versions of this attack used a different kind of loader, built with Python. WordlistLoader has now replaced it. The tool gets its name because it hides its harmful code inside a list of everyday English words. Each word stands for one small piece of the code. Gen Digital also found a version that uses coded number strings instead of words.
Once WordlistLoader finishes its job, it rebuilds hidden code that fetches the next stage of the attack, according to Gen Digital. It also uses a special trick to dodge Windows’ built-in tracking tools, so it leaves fewer clues behind.
The newest version of Amatera comes with stronger disguises. It hides its code better and slips past security checks in sneakier ways. Some of its new tricks appear to borrow ideas from another known malware tool called Remus Stealer.
Fake Microsoft Teams Chats Push SynkLoader
A separate threat, called SynkLoader, spreads through fake Microsoft Teams messages. The security firm Expel first caught this activity in mid-August 2025.
According to Expel researcher Marcus Hutchins, the attacker poses as an IT help desk worker. The fake account uses a normal-looking Microsoft email address. It messages the victim and asks them to install a program that claims to clean up their computer.
Once installed, the program secretly unpacks hidden files and runs a script in the background. That script pulls in a Python-based tool. This tool reaches out to one of three hidden control servers. It checks in every 90 to 120 seconds and waits for new instructions.
The tool can then load different add-on modules. Researchers found at least seven kinds. One studies the victim’s computer setup. Another keeps the malware running every time the computer restarts. A third module puts up a fake Windows lock screen to steal login passwords. Others let the attacker control the desktop remotely, run hidden commands, or route internet traffic through the infected machine.
Experts say it is still unclear who is behind SynkLoader. They suspect it may belong to a ransomware group or a broker who sells stolen computer access to other criminals.
Why this Matters for Everyday Users
Both WordlistLoader and SynkLoader show how creative attackers have become. Neither tool needs much effort from the victim. A single click on a fake CAPTCHA, or one downloaded file from a fake coworker, can open the door.
Avoid pasting any commands into the Windows Run box unless you trust the source completely. Real CAPTCHA checks never ask for this. Also be careful with messages from unknown “IT support” contacts, even if the email looks official.
Confirm requests like this through a separate, trusted channel before installing anything. Keep your antivirus software updated, and watch for unexpected lock screens or pop-ups asking for your password again.