Threat actors behind ClearFake campaigns are using a newly identified loader, WordlistLoader, to deliver the Amatera Stealer to Windows systems. The loader disguises executable shellcode as sequences of ordinary English words, helping malware evade static inspection before reconstructing and launching the final payload in memory. Microsoft previously observed ACR Stealer operators using fake verification prompts, […]
Read the original article: