Amatera Stealer Deployed through WebDAV Infection Chains
Cisco Talos has discovered a cryptocurrency and credentials-stealing operation using the Amatera stealer as its primary payload. The attacks began in April 2026, when Cisco observed a DLL named 'verification.google' executing from WebDAV at a Ukrainian government organization.
The investigation revealed that the Amatera builds were tasked with different secondary payloads by their respective command-and-control (C2) infrastructure. The 'pf.ch' loader was instructed to deploy a NativeAOT loader running ZigCryptoStealer and a Go-based reverse proxy, while the 'verification.google' loader was instructed to install an unauthorized instance of NetSupport Manager.
The NetSupport Manager installation contained configuration with the C2 server using an IP address based in Russia. With moderate confidence, Cisco assesses that the 'verification.google' branch attack was conducted by a Russian threat actor.