Skip to content
Amatera stealer and ZigCryptoStealer among the payloads delivered in recent ClearFake ...

Amatera stealer and ZigCryptoStealer among the payloads delivered in recent ClearFake ...

Broadcom September 8, 2026

Researchers at Cisco Talos reported on widespread credential- and cryptocurrency-harvesting operation centered on the Amatera stealer and attributed to a threat actor designated as UAT-10820. Based on endpoint telemetry findings coming from a governmental organization in Ukraine, the attackers have been observed to leverage malicious .dlls launched directly from a WebDAV . Pivoting on similar WebDAV execution patterns, another loader has been discovered where the infection workflow exploited Cloudflare Workers, BNB Smart Chain-hosted JavaScript, and deceptive Google CAPTCHA ClickFix prompts. Although both pipelines distributed the same core stealer, their secondary payloads diverged significantly. While the first observed infection chain deployed an instance of NetSupport Manager, second intrusion led to the execution of an infostealer variant called ZigCryptoStealer alongside a Go-based reverse proxy binary.

Symantec protects you from this threat, identified by the following:

Associated malicious indicators are blocked and detected by existing policies within Carbon Black products. The recommended policy at a minimum is to block all types of malware from executing (Known, Suspect, and PUP) as well as delay execution for cloud scan to get maximum benefit from Carbon Black Cloud reputation service.

Trojan.Clipbanker!ATN

Machine Learning-based

Observed domains/IPs are covered under security categories in all WebPulse enabled products

Extracted Entities