Affected Systems
Windows endpoints exposed to ClearFake/ClickFix campaigns (WordlistLoader delivering Amatera Stealer) and Microsoft Teams phishing (SynkLoader credential theft). All Windows versions vulnerable to social engineering attacks using fake CAPTCHA prompts and fake IT support contacts. Compromised legitimate websites and CDN abuse (jsdelivr) used for delivery.
Exploitation Status
Active exploitation confirmed. WordlistLoader campaigns observed from late April 2026 through August 2026 via compromised websites using ClickFix/ClearFake techniques. SynkLoader detected in active Microsoft Teams phishing campaign mid-August 2025. Multiple infection chains documented with WebDAV-based delivery and EtherHiding (blockchain-stored JavaScript) for persistence.
Business Impact
High-risk credential theft and initial access broker activity. WordlistLoader delivers Amatera Stealer (version 4.3.3-alpha1) capable of exfiltrating sensitive data with advanced evasion (ETW bypass, Heaven's Gate syscalls, application-bound encryption bypass). SynkLoader presents fake Windows lock screens to phish domain credentials. Both malware families linked to access sales for ransomware groups. Detection complicated by headless execution, WebDAV over HTTPS, legitimate CDN abuse, and minimal on-disk artifacts. User interaction required but social engineering highly effective.
Urgency
🟠Within 24 hours
Recommended Actions
- Block WebDAV client service (WebClient) on endpoints where not required; monitor registry key HKLM\SYSTEM\CurrentControlSet\Services\WebClient for unauthorized starts
- Implement application control policies to restrict rundll32.exe, mshta.exe, and conhost.exe execution from user-writable directories and remote shares
- Monitor for suspicious clipboard activity and PowerShell execution following browser interactions; alert on 'pushd' commands mapping remote shares via cmd.exe
- Block or heavily monitor cdn.jsdelivr.net at web proxy if not business-critical; hunt for Base64-encoded JavaScript injections in web server logs
- Restrict external Microsoft Teams communication to known domains; educate users on IT impersonation via Teams and verify support requests through separate channels
- Hunt for connections to compromised domains (abogadosrosarinos.com, aptisweb.com, avene-hebergement.com, https-xhamster.com, caesarjaco.co.id, skybap.shop) and Azure file storage endpoints in proxy/firewall logs
