TechNewsReel
Live

WordlistLoader and SynkLoader Use Cloud and Blockchain to Evade Detection

New loaders leverage 'ClickFix' social engineering and Microsoft Teams phishing to deploy stealers and remote access tools.

TechNewsReel Newsroom · August 24, 2026

Security researchers from Gen Digital and Expel have uncovered two distinct malware loaders, WordlistLoader and SynkLoader, designed to bypass modern defenses and establish initial access to corporate networks. These tools leverage a mix of sophisticated evasion techniques and legitimate cloud infrastructure to deliver payloads, including the Amatera Stealer.

WordlistLoader is currently utilized in ClearFake campaigns to deploy the Amatera Stealer, also known as ACR or AcridRain Stealer. The malware is delivered via the 'ClickFix' or 'FakeCaptcha' social engineering flow. According to researcher Vojtěch Krejsa, once a victim clicks an 'I'm not a robot' checkbox, they are guided through a process where a malicious command is copied to their clipboard; the victim is then instructed to paste and execute it within the Windows Run dialog.

To avoid detection, WordlistLoader employs a unique reconstruction method for its shellcode, storing it as a sequence of plain English words or UUID-encoded chunks. It further secures its presence by using hardware breakpoints to bypass Event Tracing for Windows (ETW), a primary telemetry source for security software.

Infrastructure and Distribution

The distribution of these loaders relies heavily on the abuse of trusted services. The ClickFix campaign utilizes 'EtherHiding' to store JavaScript within blockchain smart contracts and leverages the jsDelivr CDN to host malicious PowerShell scripts, complicating takedown efforts for defenders.

Simultaneously, SynkLoader targets organizations through Microsoft Teams phishing. Attackers impersonate 'IT Service Desk' personas to trick employees into downloading MSI installers. These installers are hosted on Azure blob storage, allowing the malware to blend in with legitimate Microsoft cloud traffic.

Modular Capabilities and Impact

SynkLoader is particularly dangerous due to its modular architecture. It includes a suite of tools designed for total system compromise: PhishLocker, which creates a fake lock screen to steal credentials; StreamMaster, which provides VNC-based remote access; and TrafficRedirector, which functions as a reverse proxy.

This combination of capabilities transforms the loader into a potent toolkit for initial access brokers. By providing full remote desktop control and the ability to proxy network traffic, SynkLoader allows attackers to move laterally through a network with minimal visibility.

Future Outlook

The emergence of these loaders signals a shift toward 'living-off-the-cloud' strategies, where blockchain and CDN services are used as command-and-control infrastructure. Security teams should monitor for unusual PowerShell execution originating from the Windows Run dialog and scrutinize unexpected MSI files delivered via collaboration platforms like Microsoft Teams. While the specific targets of these campaigns remain broad, the modular nature of SynkLoader suggests it may be adapted for more targeted corporate espionage in the coming months.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.