ClearFake/UAT-10820 fake-CAPTCHA chain deploys ZigCryptoStealer with EDR-killing vulnerable driver at Ukrainian government organization
Cisco Talos details a ClearFake fake-CAPTCHA infection chain, first observed at a Ukrainian government organization in April 2026, that delivers ZigCryptoStealer, Amatera, and NetSupport Manager via WebDAV-loaded rundll32 payloads and uses a BYOVD vulnerable…
ClearFake compromises websites and injects JavaScript through a malicious Cloudflare Worker, retrieving instructions from BNB Smart Chain contracts (EtherHiding). Victims are shown a fake Google CAPTCHA (ClickFix-style) that tricks Windows users into pasting a command causing rundll32 to load a remote library over WebDAV, executed as disguised DLLs with ordinal calls. The crypto-stealer branch uses DLL side-loading with a signed Chrome component to launch ZigCryptoStealer, which monitors the clipboard and swaps copied cryptocurrency wallet addresses; a signed but vulnerable Windows driver is abused in a BYOVD attack to force-terminate EDR processes. A parallel branch delivers Amatera secondary payloads that install a hidden remote-access client giving operators desktop control; the Talos newsletter additionally lists NetSupport Manager among the delivered tools. Cisco Talos, which tracks the remote-loader activity as UAT-10820 and links it with moderate confidence to a Russian-tracked actor, observed the unusual remote library execution at a Ukrainian government organization in April 2026 and assesses the attacks as an opportunistic cryptocurrency- and credential-stealing operation (the Cyber Security News report notes Talos assesses the attacks are part of a broader activity, per its truncated summary). Talos recommends monitoring rundll32.exe DLL execution with ordinal calls and robust memory scanning to detect fileless Amatera. The two reports frame attribution slightly differently: the September 9 Cyber Security News piece centers ClearFake, while Talos's September 10 newsletter attributes the campaign to UAT-10820 with moderate confidence. Talos's newsletter also covers unrelated items — an essay on burnout terminology, a Microsoft Defender 'ShieldCrash' zero-day, and a North Korean Linux espionage toolkit backdooring HAProxy — which are not part of this campaign.
- Cisco Talos observed unusual remote library execution at a Ukrainian government organization in April 2026.
- Attack chain: compromised websites inject JavaScript via a malicious Cloudflare Worker; instructions are fetched from BNB Smart Chain contracts (EtherHiding); a fake Google CAPTCHA (ClickFix) prompts users to paste a command that loads a…
- The crypto-stealer branch uses DLL side-loading with a signed Chrome component to launch ZigCryptoStealer, which monitors the clipboard and replaces copied cryptocurrency wallet addresses.
- A BYOVD attack abuses a signed but vulnerable Windows driver to force-kill EDR security tools.
- A parallel branch delivers Amatera secondary payloads installing a hidden remote-access client for operator desktop control; Talos's newsletter also lists NetSupport Manager among delivered tools.
- Attribution differs in framing: the Cyber Security News report centers the ClearFake campaign, while Talos attributes the remote-loader activity as UAT-10820 with moderate confidence, describing it as a Russian-tracked actor, and assesses…
- Talos urges monitoring rundll32.exe DLL execution with ordinal calls and robust memory scanning for fileless Amatera.
- Reports published 2026-09-09 (Cyber Security News) and 2026-09-10 (Cisco Talos Threat Source newsletter).
Coverage timelineoldest first · each row is one article
- · 7d agoClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News· 62
Cisco Talos details ClearFake's fake-CAPTCHA chain deploying ZigCryptoStealer with a BYOVD attack that kills EDR processes, observed at a Ukrainian government organization in April 2026.