As cited
Copy frozen at (site build).
threat intel
ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
Cisco Talos discovered a multi-stage infection chain delivering the Amatera stealer alongside secondary payloads including ZigCryptoStealer, a Go-based reverse proxy, and NetSupport Manager remote access tool. The ClearFake campaign uses compromised websites injected with malicious Cloudflare Workers that display fake Google CAPTCHA prompts, directing victims to execute WebDAV-hosted DLL files via Windows Run dialog. Two distinct branches observed in April and July 2026 employ different evasion techniques, blockchain-based command infrastructure, and reconnaissance to steal cryptocurrency, credentials, and messaging data from cryptocurrency wallets, password managers, and chat applications.
Why it matters: Organizations and individuals using cryptocurrency wallets, password managers, and messaging platforms are at risk of credential and wallet theft; security teams should detect and block WebDAV executions from suspicious domains, monitor for Amatera C2 communication to the identified IP addresses and domains, and identify victims through DNS queries to the six ZigCryptoStealer command domains active through July 30, 2026.
- Source published
- First seen by Cybersecurity Tracker