ClearFake/ClickFix WebDAV chain delivers Amatera (ACR Stealer), ZigCryptoStealer, and NetSupport Manager at a Ukrainian government organization; tracked as UAT-10820
Cisco Talos details a multi-stage infection chain first observed in April 2026 at a Ukrainian government organization that abuses fake Google CAPTCHA prompts (ClickFix), Cloudflare Workers, EtherHiding on BNB Smart Chain, and WebDAV DLL loaders to deliver the…
Cisco Talos investigated an infection chain first observed in April 2026, when a Ukrainian government organization executed a DLL disguised as 'verification.google' from a WebDAV UNC path via rundll32. The chain combines ClearFake JavaScript injected into compromised websites through a malicious Cloudflare Worker, EtherHiding payloads stored in BNB Smart Chain contracts (framed by Talos as abuse of bulletproof hosting on that chain), a ClickFix fake Google CAPTCHA prompt that tricks Windows users into pasting a command loading a remote library over WebDAV, and WebDAV-hosted DLL loaders that deliver the Amatera infostealer, which GBHackers additionally identifies as tracked as ACR Stealer. The Amatera configuration contained over 400 collection entries targeting browsers, messengers, crypto wallets, password managers, FTP and VPN tools, hunting for .kdbx, .p12, .pfx and .pem files. Secondary payloads differ by C2 branch: GBHackers maps the pf.ch branch to ZigCryptoStealer, launched via DLL side-loading with a signed Chrome component, hijacking clipboard cryptocurrency addresses, and paired with a Go-based reverse TCP proxy plus a signed but vulnerable Windows driver used in a BYOVD attack to force-kill EDR processes; the verification.google branch installs an unauthorized NetSupport Manager described by Cyber Security News as a hidden remote-access client giving operators desktop control, with a Russia-based C2 IP supporting attribution (Talos describes the branch split more generically as 'one loader' vs 'the other'). Talos tracks the activity as UAT-10820 and assesses with moderate confidence that it is Russian and opportunistic rather than targeted, aimed at cryptocurrency and credential theft. Detection guidance includes hunting rundll32.exe launched from WebDAV UNC paths invoking pf.ch or verification.google by ordinal, plus robust memory scanning for fileless Amatera. Similar Amatera chains were separately documented by Malwarebytes and Blackpoint Cyber with no shared infrastructure. All four reports are mutually consistent; GBHackers and Cyber Security News corroborate the chain and add the BYOVD framing, the Chrome side-loading launch, the clipboard hijack, the 400-entry configuration, and the hidden-remote-access description. Talos's Sept 10 newsletter also featured a separate essay on occupational-harm terminology (burnout, secondary traumatic stress, vicarious trauma, moral injury) and unrelated headlines not part of this story.
- First observed April 2026: a Ukrainian government organization executed a DLL disguised as 'verification.google' from a WebDAV UNC path via rundll32.
- Actor tracked as UAT-10820; assessed with moderate confidence as Russian and opportunistic (cryptocurrency and credential theft) rather than targeted.
- Chain stages: ClearFake JavaScript injected via a malicious Cloudflare Worker; EtherHiding payloads stored in BNB Smart Chain contracts (described as bulletproof hosting abuse); ClickFix fake Google CAPTCHA prompt; WebDAV-hosted DLL…
- Amatera infostealer (identified by GBHackers as also tracked as ACR Stealer) configuration held 400+ collection entries covering browsers, messengers, crypto wallets, password managers, FTP and VPN tools.
- Amatera hunts for .kdbx, .p12, .pfx and .pem files.
- pf.ch branch (per GBHackers): ZigCryptoStealer launched via DLL side-loading with a signed Chrome component and hijacks copied wallet addresses via clipboard monitoring.
- ZigCryptoStealer branch pairs a Go-based reverse TCP proxy with a signed but vulnerable Windows driver used in a BYOVD attack to force-kill EDR processes.
- verification.google branch: unauthorized NetSupport Manager installed, giving operators hidden remote-access desktop control; a Russia-based C2 IP is cited as supporting UAT-10820 attribution.
Coverage timelineoldest first · each row is one article
- · 8d agoClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
Cisco Talos· 55
Cisco Talos details ClearFake WebDAV chains delivering Amatera stealer to a Ukrainian government organization, with cryptocurrency and credential theft payloads.