CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6641

As cited

Copy frozen at (site build).

threat intel

ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager

Cisco Talos discovered a multi-stage infection chain delivering the Amatera stealer alongside secondary payloads including ZigCryptoStealer, a Go-based reverse proxy, and NetSupport Manager remote access tool. The ClearFake campaign uses compromised websites injected with malicious Cloudflare Workers that display fake Google CAPTCHA prompts, directing victims to execute WebDAV-hosted DLL files via Windows Run dialog. Two distinct branches observed in April and July 2026 employ different evasion techniques, blockchain-based command infrastructure, and reconnaissance to steal cryptocurrency, credentials, and messaging data from cryptocurrency wallets, password managers, and chat applications.

Why it matters: Organizations and individuals using cryptocurrency wallets, password managers, and messaging platforms are at risk of credential and wallet theft; security teams should detect and block WebDAV executions from suspicious domains, monitor for Amatera C2 communication to the identified IP addresses and domains, and identify victims through DNS queries to the six ZigCryptoStealer command domains active through July 30, 2026.

VendorsMicrosoftAppleGoogleCiscoGitHubDockerCloudflare
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary