THREAT OPS › Threat News › ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
<ul><li>Cisco Talos began an investigation after observing a DLL named "verification.google" executing from WebDAV at a Ukrainian government organization. We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as the primary payload. </li><li>Pi
MITRE ATT&CK techniques
Indicators of compromise
- 279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92sha256
- 643ef35536ff9273fb84b8504467b1a5645cd3ffd5476d64b99244b02131b205sha256
- 1819827e17f31e72d456158b6b9c90af25a65945f6f05d04a060da9f24179b25sha256
- bd36f4c15fe0acb6748da5ed12e45dcc37d412385812c078d1e4f04730e9f69bsha256
- 0x886d310Ac23e05EA705e24E513D19f53793832A9eth
- 0x46790e2Ac7F3CA5a7D1bfCe312d11E91d23383Ffeth
- 0x68DcE15C1002a2689E19D33A3aE509DD1fEb11A5eth
- 0x7CC3cFC1Ac007B8c6566fD2C7419b15a75473468eth
- https://www.malwarebytes.com/blog/threat-intel/2026/07/fake-games-spread-stealers-with-renpy-loader-msbuild-and-etherhidingurl
- https://blackpointcyber.com/blog/novel-fake-captcha-chain-delivering-amatera-stealer/url
- https://potentpages.com/servers/hosting/security/the-mystery-worker-in-cloudflareurl
- https://censys.com/blog/etherhiding-fake-captchas-click-fix-lures-blockchain-backed-payload-delivery/url
- https://www.joesandbox.com/analysis/1877685/0/htmlurl
- https://www.vmray.com/feature-highlight-dll-hollowing/url
- https://blog.gdatasoftware.com/2026/02/38373-pivigames-spreads-hijackloaderurl
- https://telegra.ph/Functions-04-03"url
- https://bscscan.com/address/0x7CC3cFC1Ac007B8c6566fD2C7419b15a75473468url
- https://www.vmray.com/threat-intelligence-insights-pivoting-off-the-blockchain/url
- https://kr.cedar2glanz.ru/jewel.js"url
- https://www.proofpoint.com/us/blog/threat-insight/amatera-stealer-rebranded-acr-stealer-improved-evasion-sophisticationurl
- https://phys.stunned-amniotic.com/hub.log"url
- https://www.esentire.com/blog/unpacking-netsupport-rat-loaders-delivered-via-%20%20clickfixurl
- https://www.sekoia.com/blog/meet-iclickfix-a-widespread-wordpress-targeting-f%20%20ramework-using-the-clickfix-tacticurl
- 145.249.109.147ipv4
- 45.150.34.2ipv4
- 212.118.56.166ipv4
- storage.ghost.iodomain
- bsc-testnet-rpc.publicnode.comdomain
- leaguejazire.comdomain
- riyazinikokar.xyzdomain
- bsc.rpc.blxrbdn.comdomain
- lb.propertyfind.ccdomain
- fd.gstats-api-contact.ccdomain
- pkg.vogueatelier.ccdomain
- kffd3.vogueatelier.ccdomain
- kffd3.vexlatech.ccdomain
- static.quorashift.ccdomain
- update.dubbedmuch.ccdomain
- paternal-angrily.comdomain
Original source: https://blog.talosintelligence.com/clearfake-webdav-infection-chain/