ClearFake Campaign Uses WebDAV and Fake CAPTCHAs to Deploy Stealers and Remote Access Tools
Cisco Talos has identified a ClearFake attack campaign, tracked as UAT-10820, that uses fake Google CAPTCHA pages to trick users into pasting malicious commands into the Windows Run dialog. The infection chain leverages WebDAV and BNB Smart Chain to deliver malware, with rundll32.exe loading DLLs remotely to deploy the Amatera stealer. One attack branch also installs ZigCryptoStealer and a Go-based reverse proxy, and attempts to disable endpoint detection using a vulnerable driver. A separate branch, observed at a Ukrainian government organization, progresses from Amatera to an unauthorized NetSupport Manager installation for persistent remote access. Talos recommends blocking rundll32.exe execution from internet UNC paths, restricting WebDAV access, and educating users not to paste commands from browser instructions into system dialogs.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in