WordlistLoader Delivering Amatera via ClearFake Campaigns
Score: 9/10

WordlistLoader Delivering Amatera via ClearFake Campaigns

The ClearFake campaign utilizes a new WordlistLoader to deliver Amatera Stealer (ACR Stealer) through social engineering techniques like FakeCaptcha and advanced WoW64 evasion.

Executive Summary

Gen Threat Labs has identified a new delivery mechanism for Amatera Stealer (also known as ACR Stealer) using a specialized intermediate stage called WordlistLoader. Distributed via ClearFake 'ClickFix' campaigns, attackers compromise legitimate websites to present fake CAPTCHAs that trick users into executing PowerShell commands. These commands download WordlistLoader, which reconstructs its primary shellcode from a mapping of plain English words to byte values.

Technical analysis reveals significant evolution in Amatera's defense evasion capabilities between versions 4.0.2 Beta and 4.3.3-alpha1. The malware now utilizes sophisticated techniques to bypass security monitoring, including custom WoW64 syscall gates, Heaven's Gate for x64 execution within 32-bit processes, and a revamped Application-Bound Encryption (ABE) bypass targeting Chromium-based browsers. This ABE bypass closely mirrors techniques used by Lumma and Remus stealers, indicating shared tradecraft or inspiration.

Amatera has become one of the most prevalent infostealers due to its rapid development cycle and effectiveness at evading user-mode hooks and ETW monitoring. The transition to the PoolParty process injection technique (Remote TP_DIRECT Insertion) further complicates detection for standard EDR solutions, making this threat a high priority for organizations managing Windows-based environments.

Key Details

Threat Name

Amatera Stealer

Affects

—

Adversary

—

Malware/Tools

Amatera, WordlistLoader, Remus, Lumma

Report Score

9out of 10
Quality Score
Excellent
IOC Quality9
TTP Details9
Detection Guidance6
Enterprise Relevance8
Clarity & Structure10
Technical Depth9

Sources