Cisco Talos Exposes UAT-10820 ClickFix Campaign Using Fake Google CAPTCHA, WebDAV and BNB Smart Chain to Deliver Amatera and ZigCryptoStealers
Cisco Talos details a multi-stage campaign first seen in April 2026 at a Ukrainian government organization, combining ClearFake JavaScript, EtherHiding in BNB Smart Chain contracts, fake CAPTCHA prompts and WebDAV DLL loaders to deliver the Amatera…
Cisco Talos identified a multi-stage credential- and cryptocurrency-stealing campaign first observed in April 2026, when a Ukrainian government organization executed a disguised DLL named verification.google from a WebDAV path. The chain begins with compromised websites running ClearFake JavaScript injected via malicious Cloudflare Workers, retrieves command infrastructure from BNB Smart Chain contracts (EtherHiding, described as bulletproof hosting), and presents a fake Google CAPTCHA (ClickFix social engineering) that tricks Windows users into pasting a command that loads a remote DLL over WebDAV via rundll32.exe with ordinal calls. Two branches follow: the pf.ch branch uses DLL side-loading with a signed Chrome component to launch ZigCryptoStealer, which hijacks clipboard cryptocurrency addresses, deploys a signed-but-vulnerable Windows driver in a BYOVD attack to terminate EDR processes, and sets up Go-based reverse TCP proxies. The verification.google branch installs an unauthorized NetSupport Manager client (a hidden remote-access tool giving operators desktop control) and delivers the Amatera (ACR Stealer) infostealer, whose configuration contained over 400 collection entries targeting browsers, messengers, crypto wallets, password managers, FTP and VPN tools, including .kdbx, .p12, .pfx and .pem files. Talos assesses the operation as opportunistic and attributes it with moderate confidence to the Russia-tracked actor UAT-10820 (a Russia-based C2 IP supports this). Talos recommends monitoring rundll32.exe executions from WebDAV UNC paths invoking pf.ch or verification.google by ordinal, plus robust memory scanning for fileless Amatera. Separately, Huntress (2026-09-11) dissected a distinct but thematically related campaign: a single X direct message styled as a Google Docs sidebar routed macOS users to the AMOS infostealer and Windows users to NetSupport Manager; this incident is not attributed to UAT-10820 and shares no reported infrastructure overlap beyond payload theme.
- First observed April 2026 at a Ukrainian government organization executing a disguised DLL named verification.google from a WebDAV path (Cisco Talos)
- Infection chain: compromised sites, ClearFake JavaScript via malicious Cloudflare Workers, EtherHiding instructions stored in BNB Smart Chain contracts, fake Google CAPTCHA (ClickFix), and rundll32.exe loading a remote DLL over WebDAV with…
- pf.ch branch: DLL side-loading with a signed Chrome component launches ZigCryptoStealer, which replaces copied cryptocurrency wallet addresses via clipboard hijacking
- pf.ch branch also uses a signed but vulnerable Windows driver in a BYOVD attack to terminate EDR processes, and deploys Go-based reverse TCP proxies
- verification.google branch installs unauthorized NetSupport Manager, a hidden remote-access client providing operators desktop control
- Amatera (ACR Stealer) configuration contains 400+ collection entries targeting browsers, messengers, crypto wallets, password managers, FTP and VPN tools, hunting .kdbx, .p12, .pfx and .pem files
- Amatera operates filelessly; Talos recommends robust memory scanning to detect it
- Attribution: moderate confidence to Russia-tracked UAT-10820, supported by a Russia-based C2 IP; assessed as an opportunistic cryptocurrency and credential-stealing operation
Coverage timelineoldest first · each row is one article
- · 6d agoHackers Abuse Google CAPTCHA, WebDAV and BNB Smart Chain to Deploy Credential-Stealing Malware
GBHackers· 55
Cisco Talos details ClickFix campaigns abusing fake Google CAPTCHA prompts, WebDAV and BNB Smart Chain to deploy the Amatera infostealer.
- · 6d agoClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News· 62
Cisco Talos details ClearFake's fake-CAPTCHA chain deploying ZigCryptoStealer with a BYOVD attack that kills EDR processes, observed at a Ukrainian government organization in April 2026.
- · 5d agoWe've got one word for it, and it's usually the wrong one
Cisco Talos· 32
Cisco Talos's Threat Source newsletter critiques 'burnout' terminology, describing four occupational injuries, and flags a UAT-10820 WebDAV stealer campaign at a Ukrainian government organization.
- · 4d agoGoogle Doc Sidebar Sends Mac and Windows Users Down Different Paths to Malware
Huntress· 50
Huntress analysts trace one X direct message into separate Mac and Windows malware chains delivering AMOS infostealer and NetSupport Manager RAT.