A sophisticated, multi-stage malware campaign has been observed combining fake Google CAPTCHA verification pages, WebDAV infrastructure, malicious Cloudflare Workers and BNB Smart Chain smart contracts to distribute the Amatera information stealer. The activity was identified in April 2026 after a Ukrainian government organization executed a disguised DLL named “verification.google” from a WebDAV location through the 32-bit rundll32.exe utility. Cisco Talos links this activity to the UAT-10820 cluster and assesses with moderate confidence that it represents part of a wider cryptocurrency and credential-theft campaign rather than an operation specifically aimed at the Ukrainian organization. Analysis of a related loader, “pf.ch,” helped researchers reconstruct the broader infection chain. The attack begins when compromised websites are modified with malicious Cloudflare Worker code that injects ClearFake JavaScript. Instead of relying entirely on traditional command-and-control servers, the script retrieves encoded payload information from BNB Smart Chain contracts, a technique commonly referred to as EtherHiding. The campaign used separate contracts to deliver Windows- or macOS-specific content. Windows users were presented with a fraudulent CAPTCHA-style prompt instructing them to press Windows+R, paste clipboard content and execute it. This ClickFix technique ultimately launches a WebDAV-hosted payload through rundll32.exe. Both “pf.ch” and “verification.google” follow similar execution patterns and eventually deliver Amatera, which is also known as ACR Stealer. Amatera can collect a broad range of sensitive information, including browser credentials, cryptocurrency wallet data, password databases, authentication artifacts, private keys, API tokens and data from messaging, VPN, FTP and remote-access applications. The pf.ch branch additionally delivers ZigCryptoStealer, which can manipulate copied cryptocurrency wallet addresses, while a vulnerable signed driver may be abused to terminate security processes. Another payload provides reverse-proxy capabilities, potentially enabling covert network access. The verification.google branch deploys unauthorized NetSupport Manager software and uses infrastructure associated with Russia. Defenders should monitor WebDAV-based rundll32.exe execution, suspicious Cloudflare Worker changes, BNB Smart Chain activity, abnormal Chrome DLL loading and unexpected remote-access software, while training users never to execute commands provided by CAPTCHA pages.
Healthcare technology provider Veradigm disclosed a data breach involving a third-party vendor after attackers obtained vendor credentials that provided access to a limited Veradig...
Cisco has confirmed active exploitation of CVE-2026-20079, a critical authentication-bypass vulnerability in Cisco Secure Firewall Management Center (FMC) Software with CVSS score ...
SpyCloud, a leader in identity threat protection, has released its annual 2026 SpyCloud Identity Threat Report, revealing that non-human identities (NHIs)—including AI agents, se...