Executive Summary
Gen Threat Labs has identified a new delivery mechanism for Amatera Stealer (also known as ACR Stealer) using a specialized intermediate stage called WordlistLoader. Distributed via ClearFake 'ClickFix' campaigns, attackers compromise legitimate websites to present fake CAPTCHAs that trick users into executing PowerShell commands. These commands download WordlistLoader, which reconstructs its primary shellcode from a mapping of plain English words to byte values.
Technical analysis reveals significant evolution in Amatera's defense evasion capabilities between versions 4.0.2 Beta and 4.3.3-alpha1. The malware now utilizes sophisticated techniques to bypass security monitoring, including custom WoW64 syscall gates, Heaven's Gate for x64 execution within 32-bit processes, and a revamped Application-Bound Encryption (ABE) bypass targeting Chromium-based browsers. This ABE bypass closely mirrors techniques used by Lumma and Remus stealers, indicating shared tradecraft or inspiration.
Amatera has become one of the most prevalent infostealers due to its rapid development cycle and effectiveness at evading user-mode hooks and ETW monitoring. The transition to the PoolParty process injection technique (Remote TP_DIRECT Insertion) further complicates detection for standard EDR solutions, making this threat a high priority for organizations managing Windows-based environments.
