Threats Tagged 'clearfake'
View all threats tagged with 'clearfake'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'clearfake'
Click on any threat for detailed analysis and mitigation recommendations
0 Cisco Talos identified a malware infection chain involving WebDAV-based DLL execution delivering the Amatera stealer and secondary payloads including ZigCryptoStealer and NetSupport Manager. The infection chain uses a Cloudflare Worker to inject JavaScript stored on BNB Smart Chain and a fake CAPTCHA prompt to trick victims into executing the malware. Two distinct DLL loaders named "verification.google" and "pf.ch" were observed, each deploying different secondary payloads. The "verification.google" loader installed NetSupport Manager with a command-and-control server IP linked to Russia, suggesting a Russian threat actor. The infection was first observed in April 2026 targeting a Ukrainian government organization but is assessed as not specifically targeted. Multiple infection chains delivering Amatera stealer have been documented, but no direct infrastructure links were found between them. The threat involves credential and cryptocurrency theft through sophisticated multi-stage delivery mechanisms. Join the discussion | Cisco Talos | 09/08/2026, 12:22:29 UTC Added: 09/08/2026, 10:06:36 UTC |
Threat actors exploited the EtherHiding technique to store ClearFake payload routing instructions within smart contracts on the BNB Smart Chain testnet, creating an immutable command-and-control infrastructure that cannot be taken down. The attack began with injected JavaScript on a compromised Swiss website that queried blockchain contracts to deliver malicious payloads. Victims passing anti-analysis checks were fingerprinted by operating system and routed to platform-specific ClickFix social engineering overlays. The campaign simultaneously deployed SectopRAT, a .NET-based remote access trojan capable of browser session hijacking, and ACRStealer, a C++ infostealer targeting credentials and cryptocurrency wallets. An on-chain execution tracker confirmed each compromise in real time. Four smart contracts shared a single deployer wallet, with the oldest deployed nearly a year before analysis, indicating a long-running, actively maintained operation. Join the discussion | AlienVault OTX General | 05/26/2026, 15:20:06 UTC Added: 05/27/2026, 14:03:32 UTC |
Proofpoint has identified Amatera Stealer, a rebranded version of ACR Stealer with enhanced capabilities and evasion techniques. Distributed via ClearFake website injects, it utilizes sophisticated attack chains and web injects. Amatera Stealer employs NTSockets for stealthy C2 communication, WoW64 Syscalls to bypass user-mode hooking, and supports HTTPS requests. It focuses on stealing information from browsers, crypto wallets, and various software. The malware can also execute secondary payloads. Amatera Stealer is actively developed and sold as a malware-as-a-service, with subscription plans ranging from $199 to $1,499. Join the discussion | AlienVault OTX General | 06/18/2025, 17:19:09 UTC Added: 06/18/2025, 19:46:49 UTC |
Showing 1 to 3 of 3 results