← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 28, 2026 · 13:31via Cyber Security News

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

Brief

A fake student resume is being used to place a remote-access tool on researchers’ Windows computers. The campaign hides a Windows executable inside an archive that appears to contain a graduate-school application, then opens a genuine Word document while the infection runs quietly in the background.

The lure claims to come from a recent Beijing Institute of Technology graduate seeking research work in electrical engineering, energy systems and applied AI.

That focus points to professors and laboratory staff as likely targets, rather than ordinary corporate recruiters, and turns academic correspondence into a route for intrusion.

Himanshu Anand said in a report shared with Cyber Security News (CSN) that the attack delivers SNOWLIGHT and the VShell remote-access trojan through a multi-stage, memory-based chain.

Read more on Cyber Security News