WordlistLoader and SynkLoader Abuse Trusted Surfaces

Gen Digital researchers found two new malware lines, WordlistLoader and SynkLoader, that turn trusted interfaces into access-theft paths. WordlistLoader is delivering Amatera through ClearFake ClickFix pages on compromised websites, while SynkLoader is using Microsoft Teams messages to steal Windows login credentials. ClickFix works by copying a command to the clipboard and steering the user to paste it into the Windows Run dialog, so Windows itself launches the next stage instead of a downloaded file. SynkLoader skips the fake download path and goes after credentials in Teams, which makes both flows look like ordinary user actions while they hand over access that can be resold. For defenders, the important shift is where the entry starts: not just on email or a suspicious attachment, but on a browser page or Teams interaction that users already trust. If your estate treats those surfaces as harmless collaboration or verification prompts, the compromise can begin there and end as resale-grade initial access.

Part of the PlainSec briefing for 2026-08-24

Every edition of this story: WordlistLoader and SynkLoader Abuse Trusted Surfaces

Sources