THE article discusses a critical cybersecurity alert regarding the Amatera password stealer, which exploits hundreds of compromised WordPress websites to distribute malware. Connected to the ErrTraffic Malware-as-a-Service ecosystem, attackers use a rogue WordPress plugin and persistent browser Service Workers to spread the infection through fake reCAPTCHA lures. When users execute malicious commands, they unknowingly download a fileless credential-stealing malware that disguises itself among legitimate processes.
To evade detection, the malware employs DNS-over-HTTPS and establishes encrypted sessions for data exfiltration. The article emphasizes the need for strong security measures for organizations, including monitoring for unauthorized WordPress plugins and user training to minimize the risks associated with ClickFix schemes.