Skip to main content

Threats Tagged 'amatera'

View all threats tagged with 'amatera'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: amatera

Threats Tagged 'amatera'

Click on any threat for detailed analysis and mitigation recommendations

Over a five-month period, multiple malicious campaigns operated through a single bulletproof hosting provider, AS202412 (OMEGATECH LTD, Seychelles). These campaigns used disposable domains, fake CAPTCHA pages to trick victims into executing commands, and varied infrastructure including compromised websites, cloud storage, blockchain-based C2 addresses, and trojanized installers. Despite differing payloads and methods, all campaigns initiated contact via the same hosting provider. Successful infections deployed stealers and remote access tools with persistence across reboots. Most browser visits ended at the lure page without execution.

Join the discussion

Cisco Talos identified a malware infection chain involving WebDAV-based DLL execution delivering the Amatera stealer and secondary payloads including ZigCryptoStealer and NetSupport Manager. The infection chain uses a Cloudflare Worker to inject JavaScript stored on BNB Smart Chain and a fake CAPTCHA prompt to trick victims into executing the malware. Two distinct DLL loaders named "verification.google" and "pf.ch" were observed, each deploying different secondary payloads. The "verification.google" loader installed NetSupport Manager with a command-and-control server IP linked to Russia, suggesting a Russian threat actor. The infection was first observed in April 2026 targeting a Ukrainian government organization but is assessed as not specifically targeted. Multiple infection chains delivering Amatera stealer have been documented, but no direct infrastructure links were found between them. The threat involves credential and cryptocurrency theft through sophisticated multi-stage delivery mechanisms.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: amatera
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses