Threats Tagged 'amatera'
View all threats tagged with 'amatera'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'amatera'
Click on any threat for detailed analysis and mitigation recommendations
Over a five-month period, multiple malicious campaigns operated through a single bulletproof hosting provider, AS202412 (OMEGATECH LTD, Seychelles). These campaigns used disposable domains, fake CAPTCHA pages to trick victims into executing commands, and varied infrastructure including compromised websites, cloud storage, blockchain-based C2 addresses, and trojanized installers. Despite differing payloads and methods, all campaigns initiated contact via the same hosting provider. Successful infections deployed stealers and remote access tools with persistence across reboots. Most browser visits ended at the lure page without execution. Join the discussion | AlienVault OTX General | 09/23/2026, 12:17:14 UTC Added: 09/23/2026, 13:47:50 UTC |
0 Cisco Talos identified a malware infection chain involving WebDAV-based DLL execution delivering the Amatera stealer and secondary payloads including ZigCryptoStealer and NetSupport Manager. The infection chain uses a Cloudflare Worker to inject JavaScript stored on BNB Smart Chain and a fake CAPTCHA prompt to trick victims into executing the malware. Two distinct DLL loaders named "verification.google" and "pf.ch" were observed, each deploying different secondary payloads. The "verification.google" loader installed NetSupport Manager with a command-and-control server IP linked to Russia, suggesting a Russian threat actor. The infection was first observed in April 2026 targeting a Ukrainian government organization but is assessed as not specifically targeted. Multiple infection chains delivering Amatera stealer have been documented, but no direct infrastructure links were found between them. The threat involves credential and cryptocurrency theft through sophisticated multi-stage delivery mechanisms. Join the discussion | Cisco Talos | 09/08/2026, 12:22:29 UTC Added: 09/08/2026, 10:06:36 UTC |
Showing 1 to 2 of 2 results