ClearFake WebDAV Chains Deliver Amatera, ZigCryptoStealer and Unauthorized NetSupport

· Original article ↗

Summary

Cisco Talos traced two ClearFake-related WebDAV infection chains delivering Amatera stealer. Follow-on payloads included ZigCryptoStealer, a reverse proxy, and an unauthorized NetSupport Manager installation.

Key points

  • Talos began investigating after observing a disguised DLL executed from WebDAV at a Ukrainian government organization in April 2026; it assesses with moderate confidence that the operation was not specifically targeted at that organization.
  • One reconstructed chain used a compromised website, a malicious Cloudflare Worker and JavaScript stored on BNB Smart Chain to present a fake Google CAPTCHA ClickFix prompt that led victims to execute a WebDAV-hosted DLL.
  • Both chains used disguised 32-bit DLLs launched by rundll32.exe through ordinal #1, then delivered Amatera stealer, which can collect credentials, browser and messaging data, cryptocurrency material and selected files.
  • The pf.ch branch deployed ZigCryptoStealer, which can replace cryptocurrency addresses copied to the clipboard, and a Go-based reverse TCP proxy; a vulnerable signed driver gave the loader a kernel-mode process-termination capability used against security tools.
  • The verification.google branch installed an unauthorized, concealed NetSupport Manager client configured for remote access and persistence through a scheduled task.
  • Talos assesses with moderate confidence that the verification.google activity was conducted by a Russian threat actor, citing the NetSupport command-and-control server's Russian IP address.
  • Talos published indicators of compromise and ClamAV signatures covering the ClickFix downloader, Amatera-related malware, and follow-on payloads.

Article Details

Attack Vectors
  • In the reconstructed "pf.ch" chain, a malicious Cloudflare Worker injected ClearFake JavaScript into a compromised website. The script retrieved encoded JavaScript from BNB Smart Chain contracts.
  • A fake Google CAPTCHA-style ClickFix prompt instructed Windows users to paste a command into the Run dialog. The command executed the disguised "pf.ch" DLL from WebDAV using "rundll32.exe" and ordinal #1.
  • The macOS browser stage instructed users to paste a Terminal command that requested a subdomain of "riyazinikokar[.]xyz". Cisco Talos did not pursue that branch further.
  • The "verification.google" branch was observed executing a disguised DLL from a WebDAV UNC path at a Ukrainian government organization. Cisco Talos assessed with low to medium confidence that its delivery chain was identical to the reconstructed "pf.ch" chain.
  • Amatera C2 configurations tasked the "pf.ch" branch with deploying ZigCryptoStealer and a Go reverse TCP proxy, and the "verification.google" branch with installing an unauthorized NetSupport Manager client.
Defensive Notes
  • Cisco Talos lists ClamAV signatures Win.Backdoor.BadDav-10060502-0, Win.Backdoor.GoProxShell-10060503-0, Win.Malware.AmateraStomper-10060507-0, Win.Backdoor.BadNetSup-10060508-0, and Js.Downloader.ClickFix-10060510-0 as detecting and blocking this threat.
  • The Amatera payload recovered from the "pf.ch" loader was memory-resident and was not observed being written to disk; Cisco Talos states that its memory-derived hash remains applicable to memory scanning.
  • Cisco Talos found no caller authorization check in the signed driver's process-termination IOCTL branch.

Indicators of compromise

TypeIndicatorContext
DOMAINfd[.]gstats-api-contact[.]ccHistorical ZigCryptoStealer C2 value supplied through the BNB Smart Chain contract.
DOMAINkffd3[.]vexlatech[.]ccHistorical ZigCryptoStealer C2 value supplied through the BNB Smart Chain contract.
DOMAINkffd3[.]vogueatelier[.]ccHistorical ZigCryptoStealer C2 value supplied through the BNB Smart Chain contract.
DOMAINlb[.]propertyfind[.]ccC2 domain returned by the BNB Smart Chain contract and used by ZigCryptoStealer.
DOMAINleaguejazire[.]comRandomized subdomains of this domain hosted the WebDAV path used to execute the "pf.ch" loader.
DOMAINpaternal-angrily[.]comNetSupport HTTP Gateway configured in the actor-controlled client configuration.
DOMAINpkg[.]vogueatelier[.]ccHistorical ZigCryptoStealer C2 value supplied through the BNB Smart Chain contract.
DOMAINriyazinikokar[.]xyzA subdomain was requested by the command in the malicious macOS ClickFix prompt.
DOMAINstatic[.]quorashift[.]ccHistorical ZigCryptoStealer C2 value supplied through the BNB Smart Chain contract.
DOMAINupdate[.]dubbedmuch[.]ccHardcoded C2 host in the Go reverse TCP proxy.
IPV4145[.]249[.]109[.]147C2 address decoded from the Amatera dead-drop page.
IPV4212[.]118[.]56[.]166IP address to which the configured NetSupport HTTP Gateway resolved at the time of analysis.
IPV445[.]150[.]34[.]2Encrypted bootstrap C2 address used by the "verification.google" Amatera build.
SHA2561819827e17f31e72d456158b6b9c90af25a65945f6f05d04a060da9f24179b25Unpacked Go reverse TCP proxy payload.
SHA256279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92ZIP archive delivered as an Amatera secondary payload; it contained the malicious side-loaded DLL.
SHA256643ef35536ff9273fb84b8504467b1a5645cd3ffd5476d64b99244b02131b205Shellcode blob delivered as the "pf.ch" branch's Go reverse TCP proxy payload.
SHA256bd36f4c15fe0acb6748da5ed12e45dcc37d412385812c078d1e4f04730e9f69bZIP archive downloaded by the PowerShell stage containing the unauthorized NetSupport Manager installation.
URLhxxps[:]//kr[.]cedar2glanz[.]ru/jewel[.]jsPowerShell secondary-payload URL tasked to the "verification.google" Amatera build.
URLhxxps[:]//phys[.]stunned-amniotic[.]com/hub[.]logURL from which the PowerShell stage downloaded the NetSupport Manager installation ZIP.
URLhxxps[:]//telegra[.]ph/Functions-04-03Specific dead-drop page used by the "pf.ch" Amatera build to resolve its C2 IP address.

MITRE ATT&CK

T1053.005 · Scheduled TaskThe NetSupport installation script created a scheduled task triggered at user logon.T1055.012 · Process HollowingThe NativeAOT loader started "explorer.exe" suspended, mapped a payload into the child process, changed its initial thread context, and resumed it.T1059.001 · PowerShellThe "verification.google" branch retrieved a PowerShell script with DownloadString and executed it through Invoke-Expression.T1090 · ProxyA Go secondary payload connected to its C2 over WebSocket Secure and relayed traffic between requested destinations through multiplexed streams.T1102.001 · Dead Drop ResolverAmatera resolved a C2 IP address from a Telegraph page, while ZigCryptoStealer obtained a C2 domain from a BNB Smart Chain contract.T1115 · Clipboard DataZigCryptoStealer polled the clipboard for cryptocurrency addresses and could replace matching values.T1204.004 · Malicious Copy and PasteThe fake verification prompt instructed users to paste and run a command that executed the WebDAV-hosted loader.T1218.011 · Rundll32Both WebDAV-delivered DLL loaders were executed through 32-bit "rundll32.exe" by calling ordinal #1.T1497.001 · System ChecksThe NetSupport installation script checked processor count, memory, video memory, and display-device identifiers before installing.T1497.003 · Time Based ChecksThe NetSupport installation script checked system uptime and measured whether a native delay elapsed as expected.T1562.001 · Disable or Modify ToolsThe NativeAOT loader used a vulnerable signed driver to terminate matched EDR and other security-tool processes.T1574.002 · DLL Side-LoadingA legitimate Chrome component loaded the malicious "Secur32.dll" from the delivered archive.

Threat Actors

Malware

Vendors

Products

Tools

Countries

Industries

Related Articles