Broadcom
ClearFake WebDAV Infection Chain Targets Ukrainian Government with Amatera Stealer
Article Content
Cisco Talos reported a widespread credential and cryptocurrency theft operation utilizing the Amatera stealer, identified as being linked to the threat actor UAT-10820. The attack vector involved malicious DLLs executed from a WebDAV server, with initial findings originating from a Ukrainian government organization. The infection chain exploited Cloudflare Workers and deceptive Google CAPTCHA prompts to deliver payloads, including the Amatera stealer and ZigCryptoStealer. The primary payload, Amatera, was observed being deployed alongside unauthorized instances of NetSupport Manager and ZigCryptoStealer, with command-and-control infrastructure traced back to Russia. The investigation revealed multiple delivery methods for Amatera, with no common infrastructure linking them, indicating a broader campaign. Endpoint telemetry from April 2026 triggered the investigation, revealing DLL execution patterns that were subsequently analyzed to uncover the full infection chain. The ongoing threat is characterized by its focus on cryptocurrency and credential theft, impacting governmental and potentially other sectors.
Key Points: • Amatera stealer and ZigCryptoStealer are primary payloads in a new WebDAV infection chain. • The attack is linked to the Russian threat actor UAT-10820, targeting a Ukrainian government organization. • Multiple delivery methods for Amatera have been identified, indicating a broader campaign.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.