securityonline.info 11 Sept 2026, 08:11 UTC

ClearFake WebDAV Chain Targets Crypto Users With Amatera Stealer

ClearFake WebDAV Chain Targets Crypto Users With Amatera Stealer
CyberSIXT Evidence Panel Source marked as original reporting

CISCO Talos researchers have disclosed two advanced malware delivery chains that leverage a ClearFake WebDAV infection chain to drop the Amatera credential stealer, with impacts spanning Ukrainian government networks and global cryptocurrency users. The operation hinges on compromised websites, where Cloudflare Workers inject malicious JavaScript and a ClickFix prompt impersonating Google CAPTCHA.

If a victim clicks, they unwittingly trigger a Windows command that starts the ClearFake WebDAV chain without dropping files to disk directly, ultimately facilitating credential theft and stealthy remote access.

The infection chain unfolds via disguised DLL payloads executed through rundll32[.]exe, with loader variants named “verification[.]google” and “pf[.]ch.” The pf[.]ch variant unpacks using vectored exception handling and control-flow flattening, while verification[.]google employs DLL hollowing to replace dbghelp[.]dll with the Amatera payload.

Once active, Amatera queries C2 addresses through dead-drop resolvers and proceeds to deliver secondary payloads: a ZigCryptoStealer module that clips cryptocurrency addresses from the clipboard and a Go-based reverse TCP proxy for backdoor access. A vulnerable Windows driver is also deployed to disable endpoint protections, and in another path the chain deploys NetSupport Manager. The C2 infrastructure is described as using a modified tutorial hosted on Telegra[.]ph for addresses.

Defence guidance in the piece urges monitoring for unexpected WebDAV usage and WebClient activity, disabling WebDAV where not required, flagging rundll32[.]exe calls, and watching for PowerShell queries related to uptime or video adapter RAM as signs of evasion.

View full article

Article by CyberSIXT