Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that's used to deliver next-stage payloads and likely sell access to ransomware groups.

According to findings from Gen Digital, WordlistLoader is being used to deliver Amatera Stealer (aka ACR Stealer or AcridRain Stealer) via ClearFake campaigns, which employ the ClickFix (aka FakeCaptcha) technique to dupe victims into running malicious commands under the pretext of completing CAPTCHA verification checks.

"Once the visitor clicks on the 'I'm not a robot' checkbox, they're walked through the well-known ClickFix flow, where a malicious command is copied into their clipboard and the victim is instructed to paste it into the Windows Run dialog and execute it, leading to the download of WordlistLoader that ultimately results in the execution of Amatera," security researcher Vojtěch Krejsa said.

The ClickFix prompts are displayed on real websites that have been compromised with malicious JavaScript that's injected in the form of a Base64-encoded blob. The blob, for its part, fetches another JavaScript from a smart contract stored on the blockchain, an approach known as EtherHiding, and dynamically executes the retrieved code. Some of the compromised websites serving ClickFix prompts are below -