ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
Cisco Talos identified a malware infection chain involving WebDAV-based DLL execution delivering the Amatera stealer and secondary payloads including ZigCryptoStealer and NetSupport Manager. The infection chain uses a Cloudflare Worker to inject JavaScript stored on BNB Smart Chain and a fake CAPTCHA prompt to trick victims into executing the malware. Two distinct DLL loaders named "verification.google" and "pf.ch" were observed, each deploying different secondary payloads. The "verification.google" loader installed NetSupport Manager with a command-and-control server IP linked to Russia, suggesting a Russian threat actor. The infection was first observed in April 2026 targeting a Ukrainian government organization but is assessed as not specifically targeted. Multiple infection chains delivering Amatera stealer have been documented, but no direct infrastructure links were found between them. The threat involves credential and cryptocurrency theft through sophisticated multi-stage delivery mechanisms.
AI Analysis
Technical Summary
Cisco Talos investigated a WebDAV-based malware infection chain first observed in April 2026 involving DLL execution via "rundll32.exe" from UNC WebDAV paths. Two loaders, "verification.google" and "pf.ch", were identified delivering the Amatera stealer as the primary payload. The infection chain includes a Cloudflare Worker injecting JavaScript stored on BNB Smart Chain and a fake Google CAPTCHA prompt to initiate the download and execution of Amatera. The "pf.ch" loader deployed a NativeAOT loader running ZigCryptoStealer and a Go-based reverse proxy, while the "verification.google" loader installed an unauthorized NetSupport Manager instance with a C2 server IP based in Russia. The "verification.google" activity is tracked as UAT-10820 and attributed with moderate confidence to a Russian threat actor. This campaign is part of a broader set of recent Amatera delivery chains using varied infection methods. No common infrastructure links were found between these campaigns. The infection chain targets Windows systems and aims to steal credentials and cryptocurrency.
Potential Impact
The infection chain delivers multiple malware payloads including Amatera stealer, ZigCryptoStealer, and unauthorized NetSupport Manager installations. These payloads enable credential theft, cryptocurrency theft, and remote access capabilities. The presence of a C2 server IP based in Russia linked to the NetSupport Manager installation indicates potential espionage or cybercrime motivations. The infection method using WebDAV DLL execution and fake CAPTCHA prompts increases the likelihood of successful compromise. The threat affects Windows endpoints and can lead to significant data and asset loss.
Mitigation Recommendations
No official patch or remediation guidance is provided in the source data. Since this is a malware infection chain involving social engineering and exploitation of WebDAV DLL execution, mitigation should focus on disabling or restricting WebDAV usage where not required, monitoring for suspicious DLL execution via rundll32.exe, and educating users to recognize fake CAPTCHA prompts. Endpoint detection and response solutions should be tuned to detect Amatera and related payloads. Network defenses should monitor for connections to known C2 infrastructure. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
Description
Cisco Talos identified a malware infection chain involving WebDAV-based DLL execution delivering the Amatera stealer and secondary payloads including ZigCryptoStealer and NetSupport Manager. The infection chain uses a Cloudflare Worker to inject JavaScript stored on BNB Smart Chain and a fake CAPTCHA prompt to trick victims into executing the malware. Two distinct DLL loaders named "verification.google" and "pf.ch" were observed, each deploying different secondary payloads. The "verification.google" loader installed NetSupport Manager with a command-and-control server IP linked to Russia, suggesting a Russian threat actor. The infection was first observed in April 2026 targeting a Ukrainian government organization but is assessed as not specifically targeted. Multiple infection chains delivering Amatera stealer have been documented, but no direct infrastructure links were found between them. The threat involves credential and cryptocurrency theft through sophisticated multi-stage delivery mechanisms.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Cisco Talos investigated a WebDAV-based malware infection chain first observed in April 2026 involving DLL execution via "rundll32.exe" from UNC WebDAV paths. Two loaders, "verification.google" and "pf.ch", were identified delivering the Amatera stealer as the primary payload. The infection chain includes a Cloudflare Worker injecting JavaScript stored on BNB Smart Chain and a fake Google CAPTCHA prompt to initiate the download and execution of Amatera. The "pf.ch" loader deployed a NativeAOT loader running ZigCryptoStealer and a Go-based reverse proxy, while the "verification.google" loader installed an unauthorized NetSupport Manager instance with a C2 server IP based in Russia. The "verification.google" activity is tracked as UAT-10820 and attributed with moderate confidence to a Russian threat actor. This campaign is part of a broader set of recent Amatera delivery chains using varied infection methods. No common infrastructure links were found between these campaigns. The infection chain targets Windows systems and aims to steal credentials and cryptocurrency.
Potential Impact
The infection chain delivers multiple malware payloads including Amatera stealer, ZigCryptoStealer, and unauthorized NetSupport Manager installations. These payloads enable credential theft, cryptocurrency theft, and remote access capabilities. The presence of a C2 server IP based in Russia linked to the NetSupport Manager installation indicates potential espionage or cybercrime motivations. The infection method using WebDAV DLL execution and fake CAPTCHA prompts increases the likelihood of successful compromise. The threat affects Windows endpoints and can lead to significant data and asset loss.
Defensive Guidance
No official patch or remediation guidance is provided in the source data. Since this is a malware infection chain involving social engineering and exploitation of WebDAV DLL execution, mitigation should focus on disabling or restricting WebDAV usage where not required, monitoring for suspicious DLL execution via rundll32.exe, and educating users to recognize fake CAPTCHA prompts. Endpoint detection and response solutions should be tuned to detect Amatera and related payloads. Network defenses should monitor for connections to known C2 infrastructure. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Classification
- {"confidence":0.8,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://blog.talosintelligence.com/clearfake-webdav-infection-chain/","fetched":true,"fetchedAt":"2026-09-08T10:06:36.690Z","wordCount":4057}
Threat ID: 6a9fde2cacd9273b49736a2d
Added to database: 09/08/2026, 10:06:36 UTC
Last enriched: 09/08/2026, 10:06:44 UTC
Last updated: 09/08/2026, 11:41:30 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.