ClearFake WebDAV Chains Deliver Amatera, ZigCryptoStealer and Unauthorized NetSupport

Summary
Cisco Talos traced two ClearFake-related WebDAV infection chains delivering Amatera stealer. Follow-on payloads included ZigCryptoStealer, a reverse proxy, and an unauthorized NetSupport Manager installation.
Key points
- Talos began investigating after observing a disguised DLL executed from WebDAV at a Ukrainian government organization in April 2026; it assesses with moderate confidence that the operation was not specifically targeted at that organization.
- One reconstructed chain used a compromised website, a malicious Cloudflare Worker and JavaScript stored on BNB Smart Chain to present a fake Google CAPTCHA ClickFix prompt that led victims to execute a WebDAV-hosted DLL.
- Both chains used disguised 32-bit DLLs launched by rundll32.exe through ordinal #1, then delivered Amatera stealer, which can collect credentials, browser and messaging data, cryptocurrency material and selected files.
- The pf.ch branch deployed ZigCryptoStealer, which can replace cryptocurrency addresses copied to the clipboard, and a Go-based reverse TCP proxy; a vulnerable signed driver gave the loader a kernel-mode process-termination capability used against security tools.
- The verification.google branch installed an unauthorized, concealed NetSupport Manager client configured for remote access and persistence through a scheduled task.
- Talos assesses with moderate confidence that the verification.google activity was conducted by a Russian threat actor, citing the NetSupport command-and-control server's Russian IP address.
- Talos published indicators of compromise and ClamAV signatures covering the ClickFix downloader, Amatera-related malware, and follow-on payloads.
Article Details
- Attack Vectors
- In the reconstructed "pf.ch" chain, a malicious Cloudflare Worker injected ClearFake JavaScript into a compromised website. The script retrieved encoded JavaScript from BNB Smart Chain contracts.
- A fake Google CAPTCHA-style ClickFix prompt instructed Windows users to paste a command into the Run dialog. The command executed the disguised "pf.ch" DLL from WebDAV using "rundll32.exe" and ordinal #1.
- The macOS browser stage instructed users to paste a Terminal command that requested a subdomain of "riyazinikokar[.]xyz". Cisco Talos did not pursue that branch further.
- The "verification.google" branch was observed executing a disguised DLL from a WebDAV UNC path at a Ukrainian government organization. Cisco Talos assessed with low to medium confidence that its delivery chain was identical to the reconstructed "pf.ch" chain.
- Amatera C2 configurations tasked the "pf.ch" branch with deploying ZigCryptoStealer and a Go reverse TCP proxy, and the "verification.google" branch with installing an unauthorized NetSupport Manager client.
- Defensive Notes
- Cisco Talos lists ClamAV signatures Win.Backdoor.BadDav-10060502-0, Win.Backdoor.GoProxShell-10060503-0, Win.Malware.AmateraStomper-10060507-0, Win.Backdoor.BadNetSup-10060508-0, and Js.Downloader.ClickFix-10060510-0 as detecting and blocking this threat.
- The Amatera payload recovered from the "pf.ch" loader was memory-resident and was not observed being written to disk; Cisco Talos states that its memory-derived hash remains applicable to memory scanning.
- Cisco Talos found no caller authorization check in the signed driver's process-termination IOCTL branch.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | fd[.]gstats-api-contact[.]cc | Historical ZigCryptoStealer C2 value supplied through the BNB Smart Chain contract. |
| DOMAIN | kffd3[.]vexlatech[.]cc | Historical ZigCryptoStealer C2 value supplied through the BNB Smart Chain contract. |
| DOMAIN | kffd3[.]vogueatelier[.]cc | Historical ZigCryptoStealer C2 value supplied through the BNB Smart Chain contract. |
| DOMAIN | lb[.]propertyfind[.]cc | C2 domain returned by the BNB Smart Chain contract and used by ZigCryptoStealer. |
| DOMAIN | leaguejazire[.]com | Randomized subdomains of this domain hosted the WebDAV path used to execute the "pf.ch" loader. |
| DOMAIN | paternal-angrily[.]com | NetSupport HTTP Gateway configured in the actor-controlled client configuration. |
| DOMAIN | pkg[.]vogueatelier[.]cc | Historical ZigCryptoStealer C2 value supplied through the BNB Smart Chain contract. |
| DOMAIN | riyazinikokar[.]xyz | A subdomain was requested by the command in the malicious macOS ClickFix prompt. |
| DOMAIN | static[.]quorashift[.]cc | Historical ZigCryptoStealer C2 value supplied through the BNB Smart Chain contract. |
| DOMAIN | update[.]dubbedmuch[.]cc | Hardcoded C2 host in the Go reverse TCP proxy. |
| IPV4 | 145[.]249[.]109[.]147 | C2 address decoded from the Amatera dead-drop page. |
| IPV4 | 212[.]118[.]56[.]166 | IP address to which the configured NetSupport HTTP Gateway resolved at the time of analysis. |
| IPV4 | 45[.]150[.]34[.]2 | Encrypted bootstrap C2 address used by the "verification.google" Amatera build. |
| SHA256 | 1819827e17f31e72d456158b6b9c90af25a65945f6f05d04a060da9f24179b25 | Unpacked Go reverse TCP proxy payload. |
| SHA256 | 279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92 | ZIP archive delivered as an Amatera secondary payload; it contained the malicious side-loaded DLL. |
| SHA256 | 643ef35536ff9273fb84b8504467b1a5645cd3ffd5476d64b99244b02131b205 | Shellcode blob delivered as the "pf.ch" branch's Go reverse TCP proxy payload. |
| SHA256 | bd36f4c15fe0acb6748da5ed12e45dcc37d412385812c078d1e4f04730e9f69b | ZIP archive downloaded by the PowerShell stage containing the unauthorized NetSupport Manager installation. |
| URL | hxxps[:]//kr[.]cedar2glanz[.]ru/jewel[.]js | PowerShell secondary-payload URL tasked to the "verification.google" Amatera build. |
| URL | hxxps[:]//phys[.]stunned-amniotic[.]com/hub[.]log | URL from which the PowerShell stage downloaded the NetSupport Manager installation ZIP. |
| URL | hxxps[:]//telegra[.]ph/Functions-04-03 | Specific dead-drop page used by the "pf.ch" Amatera build to resolve its C2 IP address. |
MITRE ATT&CK
T1053.005 · Scheduled TaskThe NetSupport installation script created a scheduled task triggered at user logon.T1055.012 · Process HollowingThe NativeAOT loader started "explorer.exe" suspended, mapped a payload into the child process, changed its initial thread context, and resumed it.T1059.001 · PowerShellThe "verification.google" branch retrieved a PowerShell script with DownloadString and executed it through Invoke-Expression.T1090 · ProxyA Go secondary payload connected to its C2 over WebSocket Secure and relayed traffic between requested destinations through multiplexed streams.T1102.001 · Dead Drop ResolverAmatera resolved a C2 IP address from a Telegraph page, while ZigCryptoStealer obtained a C2 domain from a BNB Smart Chain contract.T1115 · Clipboard DataZigCryptoStealer polled the clipboard for cryptocurrency addresses and could replace matching values.T1204.004 · Malicious Copy and PasteThe fake verification prompt instructed users to paste and run a command that executed the WebDAV-hosted loader.T1218.011 · Rundll32Both WebDAV-delivered DLL loaders were executed through 32-bit "rundll32.exe" by calling ordinal #1.T1497.001 · System ChecksThe NetSupport installation script checked processor count, memory, video memory, and display-device identifiers before installing.T1497.003 · Time Based ChecksThe NetSupport installation script checked system uptime and measured whether a native delay elapsed as expected.T1562.001 · Disable or Modify ToolsThe NativeAOT loader used a vulnerable signed driver to terminate matched EDR and other security-tool processes.T1574.002 · DLL Side-LoadingA legitimate Chrome component loaded the malicious "Secur32.dll" from the delivered archive.
Threat Actors
Malware
ACRStealerfrom that overwritten region. G DATA documented module stomping in a HijackLoader chain that delivered ACRStealer, using different DLLs, "evr.dll", and "rasapi32.dll" rather than the "dbghelp.dll" observed in ourAmateraClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport ManagerClearFakeClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport ManagerZigCryptoStealerClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
Vendors
Cloudflaresecond loader named "pf.ch" and allowed us to reconstruct its earlier delivery stages. The chain uses a Cloudflare Worker to inject JavaScript code stored on BNB Smart Chain and a ClickFix prompt impersonating GoogleGoogleCisco Talos began an investigation after observing a DLL named "verification.google" executing from WebDAV at a Ukrainian government organization. We assess with moderate confidence that the attacks are not targeted at
Products
BNB Smart Chainits earlier delivery stages. The chain uses a Cloudflare Worker to inject JavaScript code stored on BNB Smart Chain and a ClickFix prompt impersonating Google CAPTCHA, leading to download and execution of AmateraChromereturned configuration instructing the stealer to download a DLL side-loading package in which a signed Chrome component sideloads a malicious NativeAOT DLL, "secur32.dll". The DLL loads ZigCryptoStealer and uses amacOSWindows, it retrieves code from 0x46790e2Ac7F3CA5a7D1bfCe312d11E91d23383Ff and if the victim is running macOS, it uses 0x68DcE15C1002a2689E19D33A3aE509DD1fEb11A5. The response is Base64 decoded and evaluated asNetSupport ManagerClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport ManagerWindows2026 and it showed an execution of a DLL file through a WebDAV UNC path together with startup of the Windows WebClient service. Apart from the initial command line, we had details of the checksum of the executed
Tools
Cisco UmbrellaTalos used Cisco Umbrella to observe DNS activity for all six domains while they were active. The two most recent values also had the broadest query distribution. Umbrella data includes DNS quaries from 38 countries forClamAVThe following ClamAV signatures detect and block this threat: VirusTotalsimilar WebDAV and ordinal-execution patterns in an attempt to recover the full infection chain. Using VirusTotal, we were able to identify a full chain from a second DLL loader named "pf.ch".
Countries
BrazilQueries for the current value came most often from the United States, Indonesia, Brazil, India, and Egypt. EgyptQueries for the current value came most often from the United States, Indonesia, Brazil, India, and Egypt. IndiaQueries for the current value came most often from the United States, Indonesia, Brazil, India, and Egypt. Indonesia98 for "lb[.]propertyfind[.]cc". Queries for the current value came most often from the United States, Indonesia, Brazil, India, and Egypt. RussiaNetSupport Manager installation contained configuration with the C2 server using an IP address based in Russia. With moderate confidence, we assess that "verification.google" branch attack was conducted by a RussianUkrainedownloads "https://phys[.]stunned-amniotic[.]com/hub[.]log". Although the logs at the targeted system in Ukraine contained no evidence of accessing this URL we were able to download the file that was likely intended toUnited Statesand 98 for "lb[.]propertyfind[.]cc". Queries for the current value came most often from the United States, Indonesia, Brazil, India, and Egypt.