Amatera stealer campaigns involve cryptocurrency and credentials-stealing operations, using WebDAV and Cloudflare Workers to deliver malware payloads. The primary payload is Amatera, with secondary payloads including NativeAOT loader running ZigCryptoStealer and a Go-based reverse proxy. The threat actor uses ClickFix prompts impersonating Google CAPTCHA to download and execute the stealer. Two distinct delivery chains were observed, both using WebDAV and ordinal execution through a built-in system utility. The C2 server instructs the stealer to download DLL side-loading packages or PowerShell scripts to install NetSupport Manager remote access tools.
The threat actor behind the "verification.google" activity is assessed with moderate confidence to be Russian. This campaign is part of a wider set of recent campaigns delivering Amatera through different infection chains. The delivery chain involves a malicious Cloudflare Worker injecting JavaScript code stored on BNB Smart Chain, which queries a compromised site and injects ClearFake into the content.[/subscribe_to_unlock_form]
Amatera stealer campaigns involve cryptocurrency and credentials-stealing operations, using WebDAV and Cloudflare Workers to deliver malware payloads. The primary payload is Amatera, with secondary payloads including NativeAOT loader running ZigCryptoStealer and a Go-based reverse proxy. The threat actor uses ClickFix prompts impersonating Google CAPTCHA to download and execute the stealer. Two distinct delivery chains were observed, both using WebDAV and ordinal execution through a built-in system utility. The C2 server instructs the stealer to download DLL side-loading packages or PowerShell scripts to install NetSupport Manager remote access tools.
The threat actor behind the "verification.google" activity is assessed with moderate confidence to be Russian. This campaign is part of a wider set of recent campaigns delivering Amatera through different infection chains. The delivery chain involves a malicious Cloudflare Worker injecting JavaScript code stored on BNB Smart Chain, which queries a compromised site and injects ClearFake into the content.[emaillocker id="1283"]
The C2 server returns configuration instructing the stealer to download a DLL side-loading package or a PowerShell script. The Amatera stealer is used for cryptocurrency and credentials-stealing operations, with secondary payloads including ZigCryptoStealer and a Go-based reverse proxy. The threat actor uses WebDAV and ordinal execution through a built-in system utility to deliver malware payloads. The significance of this campaign lies in its use of Cloudflare Workers and WebDAV to deliver malware payloads.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1190 | Exploit Public | Facing Application- |
| Execution | T1059.001 | Command and Scripting Interpreter | PowerShell |
| Execution | T1059.007 | Command and Scripting Interpreter | JavaScript |
| Persistence | T1053.005 | Scheduled Task/Job | Scheduled Task |
| Credential access | T1555.003 | Credentials from Password Stores | Credentials from Web Browsers |
| Collection | T1005 | Data from Local System | - |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Command and control | T1571 | Non | Standard Port- |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | - |
| Impact | T1489 | Service Stop | - |
| Objective | Behavior ID | Behavior |
|---|---|---|
| Command & Control | B0030 | C2 Communication |
| Impact | B0022 | Remote Access |
| Discovery | E1083 | File and Directory Discovery |
| Execution | E1204 | User Execution |
| Persistence | F0012 | Registry Run Keys / Startup Folder |
| Command & Control | E1105 | Ingress Tool Transfer |
| Anti-Static Analysis | E1027 | Obfuscated Files or Information |
| Exfiltration | E1020 | Automated Exfiltration |
The following reports contain further technical details:
[/emaillocker]