ClickFix-style threat campaigns are using a new trick to evade detection and deliver Amatera, an increasingly prevalent infostealer.

August 24, 2026

A newly discovered malware loader uses lists of ordinary English words to conceal and reconstruct malicious code, helping a rapidly growing infostealer evade detection before infecting victims.

Researchers from Gen Threat Labs recently discovered WordlistLoader, a loader used to infect victims with the Amatera infostealer. As a loader, it exists between the initial infection and the final payload. Loaders can be used for a variety of purposes, such as getting deeper into a victim's machine, evading defenses, downloading and decrypting later stage malware, or launching other necessary programs.

WordlistLoader's job is to prepare the environment, evade security controls, reconstruct the next-stage payload, and then hand execution off to the infostealer. "Amatera has been actively developed over the past few months and has gradually become one of the most prevalent infostealers in our user base," Gen Threat researcher Vojtěch Krejsa wrote in the report.