ClearFake WebDAV Infection Chain Targets Ukrainian Government with Amatera Stealer

ClearFake WebDAV Infection Chain Targets Ukrainian Government with Amatera Stealer

First seen 8 Sep 2026, 21:44 UTC Blog.TalosintelligenceBroadcomblackpointcyber.comcensys.com 72.5

Article Content

Browse articles
ThreatCluster

Cisco Talos reported a widespread credential and cryptocurrency theft operation utilizing the Amatera stealer, identified as being linked to the threat actor UAT-10820. The attack vector involved malicious DLLs executed from a WebDAV server, with initial findings originating from a Ukrainian government organization. The infection chain exploited Cloudflare Workers and deceptive Google CAPTCHA prompts to deliver payloads, including the Amatera stealer and ZigCryptoStealer. The primary payload, Amatera, was observed being deployed alongside unauthorized instances of NetSupport Manager and ZigCryptoStealer, with command-and-control infrastructure traced back to Russia. The investigation revealed multiple delivery methods for Amatera, with no common infrastructure linking them, indicating a broader campaign. Endpoint telemetry from April 2026 triggered the investigation, revealing DLL execution patterns that were subsequently analyzed to uncover the full infection chain. The ongoing threat is characterized by its focus on cryptocurrency and credential theft, impacting governmental and potentially other sectors.

Key Points: • Amatera stealer and ZigCryptoStealer are primary payloads in a new WebDAV infection chain. • The attack is linked to the Russian threat actor UAT-10820, targeting a Ukrainian government organization. • Multiple delivery methods for Amatera have been identified, indicating a broader campaign.

Ask AI about this cluster

Timeline

2026-04-01
Initial DLL execution detected
Cisco Talos observed a DLL named 'verification.google' executing from WebDAV at a Ukrainian government organization, triggering the investigation.
Blog.Talosintelligence
2026-09-08
Public report on ClearFake infection chain
Cisco Talos published findings detailing the infection chain and attributed it to UAT-10820, highlighting the use of Amatera and ZigCryptoStealer.
Broadcom