ZeroHour
Cyber Security Newspublished ()ingested Tushar Subhra Dutta1
Part of a story covered by 4 sources: “Cisco Talos Exposes UAT-10820 ClickFix Campaign Using Fake Google CAPTCHA, WebDAV and BNB Smart Chain to Deliver Amatera and ZigCryptoStealers” — merged summary and timeline →

ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools

mediumMalware exploited in the wildimportance 62
AI summary · glm-5.3-flash

Cisco Talos details ClearFake's fake-CAPTCHA chain deploying ZigCryptoStealer with a BYOVD attack that kills EDR processes, observed at a Ukrainian government organization in April 2026.

ClearFake compromises websites, injects JavaScript via a malicious Cloudflare Worker, retrieves instructions from BNB Smart Chain contracts (EtherHiding), and presents a fake Google CAPTCHA that tricks Windows users into pasting a command that loads a remote library over WebDAV via rundll32. The crypto-stealer branch uses DLL side-loading with a signed Chrome component to launch ZigCryptoStealer, which hijacks clipboard cryptocurrency addresses, alongside a signed but vulnerable Windows driver used in a BYOVD attack to terminate EDR processes. A parallel branch delivers Amatera secondary payloads that install a hidden remote-access client providing operator desktop control, with Cisco Talos tracking the remote-loader activity as UAT-10820. Talos observed unusual remote library execution at a Ukrainian government organization in April 2026 and assesses the attacks are part of a broader theft operation rather than a single targeted campaign.

  • ClickFix fake CAPTCHA prompts users to run WebDAV-delivered rundll32 payloads
  • ZigCryptoStealer replaces copied wallet addresses via clipboard monitoring
  • BYOVD technique uses a signed vulnerable driver to force-kill EDR tools
  • EtherHiding fetches command infrastructure from BNB Smart Chain contracts
  • Tracked as UAT-10820; first seen at a Ukrainian government organization

Indicators of compromiseAll →

TypeIndicatorContext
domainbsc.rpc.blxrbdn.come-loaded by the Chrome component BNB Smart Chain RPC domain bsc[.]rpc[.]blxrbdn[.]com RPC endpoint queried by ZigCryptoStealer BNB Smart Ch
domainbsc-testnet-rpc.publicnode.comCs):- Type Indicator Description BNB Smart Chain RPC domain bsc-testnet-rpc[.]publicnode[.]com RPC service queried by the initial ClearFake browser sc
domainfd.gstats-api-contact.cced by ZigCryptoStealer to obtain C2 configuration C2 domain fd[.]gstats-api-contact[.]cc Historical ZigCryptoStealer contract value C2 domain pk
domaingithub.comaddress for the verification.google branch TLS SNI and Host github[.]com Hostname presented by the verification.google Amatera bui
domainhub.logwerShell download URL hxxps://phys[.]stunned-amniotic[.]com/hub[.]log ZIP payload retrieved by the PowerShell installer SHA-256
domainjewel.jsproxy PowerShell payload URL hxxps://kr[.]cedar2glanz[.]ru/jewel[.]js Secondary PowerShell payload for the verification.google
domainkffd3.vexlatech.ccr[.]cc Historical ZigCryptoStealer contract value C2 domain kffd3[.]vexlatech[.]cc Historical ZigCryptoStealer contract value C2 domain st
domainkffd3.vogueatelier.ccr[.]cc Historical ZigCryptoStealer contract value C2 domain kffd3[.]vogueatelier[.]cc Historical ZigCryptoStealer contract value C2 domain kf
domainkr.cedar2glanz.runt for the reverse TCP proxy PowerShell payload URL hxxps://kr[.]cedar2glanz[.]ru/jewel[.]js Secondary PowerShell payload for the verific
domainlb.propertyfind.cct[.]cc Historical ZigCryptoStealer contract value C2 domain lb[.]propertyfind[.]cc ZigCryptoStealer C2 domain returned during analysis Dri
domainleaguejazire.com1fEb11A5 macOS-specific second-stage contract WebDAV domain leaguejazire[.]com Randomized subdomains used for Windows WebDAV delivery Do
domainpaternal-angrily.comion file for the remote-access client Remote-access gateway paternal-angrily[.]com:443 Configured remote-access HTTP gateway IPv4 address 21
domainphys.stunned-amniotic.comverification.google branch PowerShell download URL hxxps://phys[.]stunned-amniotic[.]com/hub[.]log ZIP payload retrieved by the PowerShell insta
domainpkg.vogueatelier.cct[.]cc Historical ZigCryptoStealer contract value C2 domain pkg[.]vogueatelier[.]cc Historical ZigCryptoStealer contract value C2 domain kf
domainriyazinikokar.xyzndomized subdomains used for Windows WebDAV delivery Domain riyazinikokar[.]xyz macOS ClickFix request infrastructure File name pf.ch Web
domainstatic.quorashift.cch[.]cc Historical ZigCryptoStealer contract value C2 domain static[.]quorashift[.]cc Historical ZigCryptoStealer contract value C2 domain lb
domaintelegra.phbserved at the Ukrainian organization Dead-drop URL hxxps://telegra[.]ph/Functions-04-03 Public page used by the Amatera branch to
domainupdate.dubbedmuch.cced Go-based reverse TCP proxy executable WebSocket C2 wss://update[.]dubbedmuch[.]cc/ Hard-coded C2 endpoint for the reverse TCP proxy Power
sha2561819827e17f31e72d456158b6b9c90af25a65945f6f05d04a060da9f24179b25ode payload used to deploy the Go reverse TCP proxy SHA-256 1819827e17f31e72d456158b6b9c90af25a65945f6f05d04a060da9f24179b25 Unpacked Go-based reverse TCP proxy executable WebSocket C2
sha256279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92ation.google Amatera build during C2 communications SHA-256 279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92 ZIP archive containing the DLL side-loading package File na
sha256643ef35536ff9273fb84b8504467b1a5645cd3ffd5476d64b99244b02131b205ce\DCRCVDRV_U Driver device exposed by DCRCVDrv.sys SHA-256 643ef35536ff9273fb84b8504467b1a5645cd3ffd5476d64b99244b02131b205 Shellcode payload used to deploy the Go reverse TCP proxy S
sha256bd36f4c15fe0acb6748da5ed12e45dcc37d412385812c078d1e4f04730e9f69bg ZIP payload retrieved by the PowerShell installer SHA-256 bd36f4c15fe0acb6748da5ed12e45dcc37d412385812c078d1e4f04730e9f69b ZIP archive containing the unauthorized remote-access deplo
urlhttps://kr[2 endpoint for the reverse TCP proxy PowerShell payload URL hxxps://kr[.]cedar2glanz[.]ru/jewel[.]js Secondary PowerShell payload f
urlhttps://phys[for the verification.google branch PowerShell download URL hxxps://phys[.]stunned-amniotic[.]com/hub[.]log ZIP payload retrieved by
urlhttps://telegra[loader observed at the Ukrainian organization Dead-drop URL hxxps://telegra[.]ph/Functions-04-03 Public page used by the Amatera branch
Full article1,119 words · extracted from cybersecuritynews.com · click to collapse

ClearFake has expanded a fake CAPTCHA scam into a chain that steals cryptocurrency and credentials while disabling endpoint protection. It turns compromised websites into launchpads, relying on visitors to run a command that appears routine.

The operation begins with injected browser code, blockchain-hosted instructions, and a ClickFix prompt styled as a Google CAPTCHA. After a user follows the steps, a remote loader retrieves and runs a disguised library through WebDAV.

Cisco Talos analysts identified the activity after seeing unusual remote library execution at a Ukrainian government organization in April 2026. They assess the observed attacks were part of a broader theft operation, not one campaign aimed at that organization.

The consequences can extend beyond stolen browser data. One branch installs a crypto stealer that changes copied wallet addresses, while another can provide remote control to an operator. This gives attackers a route from one deceptive webpage to persistent access and financial theft.

Cisco Talos said in a report shared with Cyber Security News (CSN) that it tracked the activity linked to the remote-loader branch as UAT-10820.

ClearFake Deploys Crypto Stealer

In the crypto-stealer branch, the first payload receives instructions to fetch an archive. A legitimate, signed Chrome component inside that archive is abused to load a malicious library placed beside it, a technique called DLL side-loading.

Parallel WebDAV infection chains and Amatera secondary payloads (Source - Cisco Talos)
Parallel WebDAV infection chains and Amatera secondary payloads (Source – Cisco Talos)

That library launches ZigCryptoStealer and a signed but vulnerable Windows driver. The loader searches for EDR products and sends matching process identifiers to the driver, which can force them to stop.

This is a bring-your-own-vulnerable-driver, or BYOVD, attack. A driver works deep inside Windows, so process killing can undermine protections that watch the device. Similar driver attacks against EDR tools show why signed code alone cannot be treated as safe.

With defenses weakened, ZigCryptoStealer monitors the clipboard for cryptocurrency addresses. It can replace a copied address with one controlled by the attacker, potentially redirecting a payment without an obvious warning to the victim.

The malware also uses a blockchain contract to obtain changing command infrastructure. That approach, known as EtherHiding, allows operators to update where the stealer communicates without changing the code delivered to an infected computer.

This lets attackers change campaigns quickly and keep malicious content away from their primary delivery infrastructure. Earlier Amatera stealer web campaigns illustrate how ClearFake operators have repeatedly paired hacked sites with fake verification screens.

From Fake CAPTCHA to Control

The delivery chain starts when attackers compromise a website and inject JavaScript through a malicious Cloudflare Worker. The script checks the visitor environment and retrieves more code from BNB Smart Chain before covering the page with a convincing verification prompt.

The prompt instructs Windows visitors to open the Run dialog, paste clipboard content, and press Enter. That action launches a command that accesses a remote WebDAV path and calls rundll32, a legitimate Windows utility, to execute a library export identified only by a number.

Windows ClickFix verification prompt (Source - Cisco Talos)
Windows ClickFix verification prompt (Source – Cisco Talos)

This design shifts the crucial execution step to the victim, avoiding the need for a browser exploit. The approach matches a ClickFix WebDAV delivery technique that uses trusted Windows components to load remote malware while obscuring the command’s purpose.

A separate branch uses the same general WebDAV pattern but eventually runs a PowerShell script that installs an unauthorized remote-access client. It hides the client interface, connects to an attacker gateway, and creates a task that starts at logon.

That remote-access capability raises the stakes. Automated theft can collect passwords, session data, wallet material, and selected files, while a human operator may then browse the desktop, transfer files, run commands, or deploy more malware.

Related fake CAPTCHA malware attacks show the same social-engineering model remains effective across changing loaders.

Organizations should teach staff that legitimate CAPTCHA checks never require opening Run, Terminal, PowerShell, or Command Prompt and pasting a command.

Security teams should investigate unusual WebDAV traffic, ordinal-based rundll32 execution, unexpected driver services, and new scheduled tasks, and should use driver blocklists and vulnerable-driver protections.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
BNB Smart Chain RPC domainbsc-testnet-rpc[.]publicnode[.]comRPC service queried by the initial ClearFake browser script
BNB Smart Chain contract0x886d310Ac23e05EA705e24E513D19f53793832A9Initial contract used to retrieve encoded malicious JavaScript
BNB Smart Chain contract0x46790e2Ac7F3CA5a7D1bfCe312d11E91d23383FfWindows-specific second-stage contract
BNB Smart Chain contract0x68DcE15C1002a2689E19D33A3aE509DD1fEb11A5macOS-specific second-stage contract
WebDAV domainleaguejazire[.]comRandomized subdomains used for Windows WebDAV delivery
Domainriyazinikokar[.]xyzmacOS ClickFix request infrastructure
File namepf.chWebDAV-delivered DLL loader
File nameverification.googleWebDAV-delivered DLL loader observed at the Ukrainian organization
Dead-drop URLhxxps://telegra[.]ph/Functions-04-03Public page used by the Amatera branch to resolve C2
IPv4 address145.249.109[.]147:443Resolved Amatera command-and-control server for the pf.ch branch
IPv4 address45.150.34[.]2:443Bootstrap C2 address for the verification.google branch
TLS SNI and Hostgithub[.]comHostname presented by the verification.google Amatera build during C2 communications
SHA-256279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92ZIP archive containing the DLL side-loading package
File nameplatform_experience_helper.exeSigned Chrome component abused for DLL side-loading
File nameSecur32.dllMalicious NativeAOT loader side-loaded by the Chrome component
BNB Smart Chain RPC domainbsc[.]rpc[.]blxrbdn[.]comRPC endpoint queried by ZigCryptoStealer
BNB Smart Chain contract0x7CC3cFC1Ac007B8c6566fD2C7419b15a75473468Contract used by ZigCryptoStealer to obtain C2 configuration
C2 domainfd[.]gstats-api-contact[.]ccHistorical ZigCryptoStealer contract value
C2 domainpkg[.]vogueatelier[.]ccHistorical ZigCryptoStealer contract value
C2 domainkffd3[.]vogueatelier[.]ccHistorical ZigCryptoStealer contract value
C2 domainkffd3[.]vexlatech[.]ccHistorical ZigCryptoStealer contract value
C2 domainstatic[.]quorashift[.]ccHistorical ZigCryptoStealer contract value
C2 domainlb[.]propertyfind[.]ccZigCryptoStealer C2 domain returned during analysis
Driver file nameDCRCVDrv.sysSigned vulnerable driver used to terminate security processes
Device path\Device\DCRCVDRV_UDriver device exposed by DCRCVDrv.sys
SHA-256643ef35536ff9273fb84b8504467b1a5645cd3ffd5476d64b99244b02131b205Shellcode payload used to deploy the Go reverse TCP proxy
SHA-2561819827e17f31e72d456158b6b9c90af25a65945f6f05d04a060da9f24179b25Unpacked Go-based reverse TCP proxy executable
WebSocket C2wss://update[.]dubbedmuch[.]cc/Hard-coded C2 endpoint for the reverse TCP proxy
PowerShell payload URLhxxps://kr[.]cedar2glanz[.]ru/jewel[.]jsSecondary PowerShell payload for the verification.google branch
PowerShell download URLhxxps://phys[.]stunned-amniotic[.]com/hub[.]logZIP payload retrieved by the PowerShell installer
SHA-256bd36f4c15fe0acb6748da5ed12e45dcc37d412385812c078d1e4f04730e9f69bZIP archive containing the unauthorized remote-access deployment
File namehypersnap.exeRenamed remote-access client launched by the PowerShell script
File nameclient32.iniActor-controlled configuration file for the remote-access client
Remote-access gatewaypaternal-angrily[.]com:443Configured remote-access HTTP gateway
IPv4 address212.118.56[.]166IP address resolving from the remote-access gateway during analysis

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/clearfake-deploys-crypto-stealer/