This leads to the execution of a VBScript loader that decodes and runs PowerShell designed to fetch a JPEG image from an image-hosting service and extract it from the stealer payload in memory to minimize on-disk artifacts and complicate detection and analysis.
“The primary purpose of WordlistLoader, an intermediate stage in the Amatera infection chain, is to reconstruct a shellcode that serves as the entry point for subsequent stages,” Gen Digital said. At the same time, it employs a hardware-breakpoint-based method to bypass Event Tracing for Windows (ETW) and avoid leaving traces of malicious activity.
WordlistLoader gets its name from the fact that the shellcode is stored in encoded form as a sequence of plain English words, with each word representing one byte. Gen said it also identified a variant that replaces the wordlist with an array of 16-byte UUID-encoded chunks.









