ZeroHour
Story · 1 source · 1 articlefirst updated ()

ClearFake/UAT-10820 fake-CAPTCHA chain deploys ZigCryptoStealer with EDR-killing vulnerable driver at Ukrainian government organization

mediumMalwareexploited in the wildimportance 62
What's new: First merged summary (no prior version). The Cisco Talos report (2026-09-10) adds: moderate-confidence attribution of the remote-loader activity to UAT-10820, described as a Russian-tracked actor; an assessment of the campaign as opportunistic cryptocurrency and credential stealing; NetSupport Manager as an additional delivered tool alongside ZigCryptoStealer and Amatera; and detection guidance…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Cisco Talos details a ClearFake fake-CAPTCHA infection chain, first observed at a Ukrainian government organization in April 2026, that delivers ZigCryptoStealer, Amatera, and NetSupport Manager via WebDAV-loaded rundll32 payloads and uses a BYOVD vulnerable…

ClearFake compromises websites and injects JavaScript through a malicious Cloudflare Worker, retrieving instructions from BNB Smart Chain contracts (EtherHiding). Victims are shown a fake Google CAPTCHA (ClickFix-style) that tricks Windows users into pasting a command causing rundll32 to load a remote library over WebDAV, executed as disguised DLLs with ordinal calls. The crypto-stealer branch uses DLL side-loading with a signed Chrome component to launch ZigCryptoStealer, which monitors the clipboard and swaps copied cryptocurrency wallet addresses; a signed but vulnerable Windows driver is abused in a BYOVD attack to force-terminate EDR processes. A parallel branch delivers Amatera secondary payloads that install a hidden remote-access client giving operators desktop control; the Talos newsletter additionally lists NetSupport Manager among the delivered tools. Cisco Talos, which tracks the remote-loader activity as UAT-10820 and links it with moderate confidence to a Russian-tracked actor, observed the unusual remote library execution at a Ukrainian government organization in April 2026 and assesses the attacks as an opportunistic cryptocurrency- and credential-stealing operation (the Cyber Security News report notes Talos assesses the attacks are part of a broader activity, per its truncated summary). Talos recommends monitoring rundll32.exe DLL execution with ordinal calls and robust memory scanning to detect fileless Amatera. The two reports frame attribution slightly differently: the September 9 Cyber Security News piece centers ClearFake, while Talos's September 10 newsletter attributes the campaign to UAT-10820 with moderate confidence. Talos's newsletter also covers unrelated items — an essay on burnout terminology, a Microsoft Defender 'ShieldCrash' zero-day, and a North Korean Linux espionage toolkit backdooring HAProxy — which are not part of this campaign.

  • Cisco Talos observed unusual remote library execution at a Ukrainian government organization in April 2026.
  • Attack chain: compromised websites inject JavaScript via a malicious Cloudflare Worker; instructions are fetched from BNB Smart Chain contracts (EtherHiding); a fake Google CAPTCHA (ClickFix) prompts users to paste a command that loads a…
  • The crypto-stealer branch uses DLL side-loading with a signed Chrome component to launch ZigCryptoStealer, which monitors the clipboard and replaces copied cryptocurrency wallet addresses.
  • A BYOVD attack abuses a signed but vulnerable Windows driver to force-kill EDR security tools.
  • A parallel branch delivers Amatera secondary payloads installing a hidden remote-access client for operator desktop control; Talos's newsletter also lists NetSupport Manager among delivered tools.
  • Attribution differs in framing: the Cyber Security News report centers the ClearFake campaign, while Talos attributes the remote-loader activity as UAT-10820 with moderate confidence, describing it as a Russian-tracked actor, and assesses…
  • Talos urges monitoring rundll32.exe DLL execution with ordinal calls and robust memory scanning for fileless Amatera.
  • Reports published 2026-09-09 (Cyber Security News) and 2026-09-10 (Cisco Talos Threat Source newsletter).

Coverage timeline

  1. · 7d ago
    Cyber Security News· 62
    ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools

    Cisco Talos details ClearFake's fake-CAPTCHA chain deploying ZigCryptoStealer with a BYOVD attack that kills EDR processes, observed at a Ukrainian government organization in April 2026.