Threat Advisory

Amatera Password Stealer Uses ClickFix Chain and EtherHiding

Threat: Malware
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A WordPress mass-compromise campaign affecting hundreds of sites. The rogue must-use plugin registers a Service Worker in the visitor’s browser, which strips the site’s Content-Security-Policy header and injects a script that reads its payload from a smart contract on Base. The threat employs Service Worker persistence, EtherHiding on-chain payload delivery, fake reCAPTCHA, and ClickFix. It also adds a disguised polyglot file, mshta abuse, a fileless PowerShell stage, an image-hidden loader, and finally the Amatera password stealer.

The campaign’s design choice is to have no durable artifacts to act on, making it challenging for defenders. The threat operates as a ladder, with each rung built to defeat one specific defense. It starts with a compromised WordPress site, followed by a malicious Service Worker that survives site cleanup and strips CSP.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A WordPress mass-compromise campaign affecting hundreds of sites. The rogue must-use plugin registers a Service Worker in the visitor’s browser, which strips the site’s Content-Security-Policy header and injects a script that reads its payload from a smart contract on Base. The threat employs Service Worker persistence, EtherHiding on-chain payload delivery, fake reCAPTCHA, and ClickFix. It also adds a disguised polyglot file, mshta abuse, a fileless PowerShell stage, an image-hidden loader, and finally the Amatera password stealer.

The campaign’s design choice is to have no durable artifacts to act on, making it challenging for defenders. The threat operates as a ladder, with each rung built to defeat one specific defense. It starts with a compromised WordPress site, followed by a malicious Service Worker that survives site cleanup and strips CSP.[emaillocker id="1283"]

The next layer involves a Base smart contract holding the payload (EtherHiding), a fake reCAPTCHA prompt, an MP3/HTA polyglot, a scheduled task and PowerShell stage, an Emmenhtal loader with steganographic image on a legitimate CDN, a reflective loader that never writes the payload to disk, and finally the Amatera password stealer calling home over DNS-over-HTTPS.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1566.003 Phishing Spearphishing via Service
Execution T1059.001 Command and Scripting Interpreter PowerShell
Execution T1203 Exploitation for Client Execution -
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
Defence Evasion T1027.002 Obfuscated Files or Information Software Packing
Defence Evasion T1036.005 Masquerading Match Legitimate Resource Name or Location
Defence Evasion T1070.004 Indicator Removal File Deletion
Credential access T1555.003 Credentials from Password Stores Credentials from Web Browsers
Command and control T1071.001 Application Layer Protocol Web Protocols
Exfiltration T1041 Exfiltration Over C2 Channel -

MBC MAPPING:

Objective Behavior ID Behavior
Anti-Behavioral Analysis B0003 Dynamic Analysis Evasion
Defense Evasion B0029 Polymorphic Code
Anti-Static Analysis B0032 Executable Code Obfuscation
Command & Control B0030 C2 Communication
Impact B0022 Remote Access
Discovery E1083 File and Directory Discovery
Execution E1204 User Execution
Exfiltration E1020 Automated Exfiltration
Persistence F0012 Registry Run Keys / Startup Folder
Anti-Static Analysis E1027 Obfuscated Files or Information
Defense Evasion F0004 Disable or Evade Security Tools

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu