Threat Advisory

Amatera Stealer Deployed via WebDAV and Cloudflare Worker

Threat: Malware
Targeted Region: Ukraine, Russia, United States, India
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Amatera stealer campaigns involve cryptocurrency and credentials-stealing operations, using WebDAV and Cloudflare Workers to deliver malware payloads. The primary payload is Amatera, with secondary payloads including NativeAOT loader running ZigCryptoStealer and a Go-based reverse proxy. The threat actor uses ClickFix prompts impersonating Google CAPTCHA to download and execute the stealer. Two distinct delivery chains were observed, both using WebDAV and ordinal execution through a built-in system utility. The C2 server instructs the stealer to download DLL side-loading packages or PowerShell scripts to install NetSupport Manager remote access tools.

The threat actor behind the "verification.google" activity is assessed with moderate confidence to be Russian. This campaign is part of a wider set of recent campaigns delivering Amatera through different infection chains. The delivery chain involves a malicious Cloudflare Worker injecting JavaScript code stored on BNB Smart Chain, which queries a compromised site and injects ClearFake into the content.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Amatera stealer campaigns involve cryptocurrency and credentials-stealing operations, using WebDAV and Cloudflare Workers to deliver malware payloads. The primary payload is Amatera, with secondary payloads including NativeAOT loader running ZigCryptoStealer and a Go-based reverse proxy. The threat actor uses ClickFix prompts impersonating Google CAPTCHA to download and execute the stealer. Two distinct delivery chains were observed, both using WebDAV and ordinal execution through a built-in system utility. The C2 server instructs the stealer to download DLL side-loading packages or PowerShell scripts to install NetSupport Manager remote access tools.

The threat actor behind the "verification.google" activity is assessed with moderate confidence to be Russian. This campaign is part of a wider set of recent campaigns delivering Amatera through different infection chains. The delivery chain involves a malicious Cloudflare Worker injecting JavaScript code stored on BNB Smart Chain, which queries a compromised site and injects ClearFake into the content.[emaillocker id="1283"]

The C2 server returns configuration instructing the stealer to download a DLL side-loading package or a PowerShell script. The Amatera stealer is used for cryptocurrency and credentials-stealing operations, with secondary payloads including ZigCryptoStealer and a Go-based reverse proxy. The threat actor uses WebDAV and ordinal execution through a built-in system utility to deliver malware payloads. The significance of this campaign lies in its use of Cloudflare Workers and WebDAV to deliver malware payloads.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1190 Exploit Public Facing Application-
Execution T1059.001 Command and Scripting Interpreter PowerShell
Execution T1059.007 Command and Scripting Interpreter JavaScript
Persistence T1053.005 Scheduled Task/Job Scheduled Task
Credential access T1555.003 Credentials from Password Stores Credentials from Web Browsers
Collection T1005 Data from Local System -
Command and control T1071.001 Application Layer Protocol Web Protocols
Command and control T1571 Non Standard Port-
Exfiltration T1041 Exfiltration Over C2 Channel -
Impact T1489 Service Stop -

MBC MAPPING:

Objective Behavior ID Behavior
Command & Control B0030 C2 Communication
Impact B0022 Remote Access
Discovery E1083 File and Directory Discovery
Execution E1204 User Execution
Persistence F0012 Registry Run Keys / Startup Folder
Command & Control E1105 Ingress Tool Transfer
Anti-Static Analysis E1027 Obfuscated Files or Information
Exfiltration E1020 Automated Exfiltration

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu