DEV Community

Mark0
Mark0

Posted on

ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager

Cisco Talos recently uncovered a sophisticated malware campaign utilizing the Amatera stealer (formerly ACR stealer) delivered through a complex infection chain. The operation leverages "EtherHiding," a technique where malicious JavaScript is stored on the BNB Smart Chain blockchain and injected into compromised websites via Cloudflare Workers. Victims are targeted with "ClickFix" lures—fake Google CAPTCHA prompts—that trick users into executing commands which download and launch malicious DLLs via WebDAV UNC paths.

The investigation highlighted two distinct branches of activity: the "pf.ch" loader and the "verification.google" loader. The first branch deploys ZigCryptoStealer along with a Go-based reverse proxy, using a vulnerable driver to terminate EDR software (BYOVD). The second branch, observed at a Ukrainian government organization, installs a modified NetSupport Manager instance for remote access. Infrastructure analysis points toward a Russian threat actor for the latter, emphasizing a trend of using decentralized hosting and legitimate remote management tools for credential and cryptocurrency theft.


Read Full Article

Top comments (0)