WordlistLoader Disguises Malware as Ordinary Text in ClickFix Campaigns
New evasion technique delivers Amatera infostealer to unsuspecting users

Key Takeaways
- WordlistLoader is being used in ClickFix-style campaigns to deliver the Amatera infostealer.
- The malware disguises its payload as ordinary text to evade detection.
- The technique relies on social engineering rather than software exploitation.
- No specific patch is available; mitigation focuses on awareness and endpoint detection.
Quick answers
- What happened?
- Threat actors have adopted a ClickFix-style campaign tactic using a tool identified as WordlistLoader to deliver the Amatera infostealer. The malware disguises its payload as ordinary text, evading initial detection and relying on social engineering to execute on target systems.
- What should defenders do?
- Organizations should update endpoint detection and response (EDR) rules to monitor for anomalous text file execution behaviors. Security teams should advise users to avoid interacting with unsolicited text files or documents from unknown sources. Implementing application control to restrict execution of files from untrusted sources is recommended. Regular security awareness training focusing on social engineering tactics associated with ClickFix-style campaigns is advised.
According to recent reporting, ClickFix-style threat campaigns are leveraging a new evasion technique to distribute the Amatera infostealer. The mechanism, identified as WordlistLoader, disguises malicious payloads as ordinary text files, allowing them to bypass security controls that may flag executable or archive files. When a user interacts with the disguised text, the loader executes and delivers the Amatera infostealer, which is described as increasingly prevalent in the current threat landscape. The attack follows the ClickFix social engineering pattern, where users are tricked into performing actions that compromise their systems. While the specific delivery vectors and target organizations are not detailed in the reporting, the technique represents a shift toward using legitimate-looking file types to evade endpoint detection. The reporting emphasizes that no specific software vulnerability is exploited; rather, the method relies on user interaction and the legitimacy of the text disguise. Security analysts recommend heightened awareness and updated endpoint detection capabilities to identify such file-based social engineering attempts.
Security Details
WordlistLoader disguises malicious payloads as ordinary text files to evade detection. The loader executes upon user interaction and delivers the Amatera infostealer, which exfiltrates sensitive data from the compromised system. The technique does not exploit a software vulnerability but relies on social engineering and the legitimacy of the text file disguise.
Mitigation
Organizations should update endpoint detection and response (EDR) rules to monitor for anomalous text file execution behaviors. Security teams should advise users to avoid interacting with unsolicited text files or documents from unknown sources. Implementing application control to restrict execution of files from untrusted sources is recommended. Regular security awareness training focusing on social engineering tactics associated with ClickFix-style campaigns is advised.
Sources
Dark reading
Foul Language: WordlistLoader Disguises Malware as Ordinary Text
Aug 24, 2026 · 20:51
Original link
Related Security News

Star Blizzard Campaign Targets 100+ Organizations with Fake Event Invitations
Microsoft reports that the Russian state-sponsored threat actor Star Blizzard has been conducting a sustained campaign since January 2026, using fake event invitations to trick targets into installing a backdoor on Windows computers. The operation has affected more than 100 organizations, primarily in the U.S. and U.K., with victims tied to Ukraine. At least one infection has been confirmed, though the full extent of breaches and data exfiltration remains unverified.




