Executive Summary
In April 2026, Cisco Talos identified a sophisticated infection campaign targeting various organizations, including a Ukrainian government entity, attributed to the Russian threat actor UAT-10820. The campaign utilizes the 'ClearFake' framework, which leverages malicious Cloudflare Workers and 'EtherHiding'—a technique where malicious JavaScript is stored on the BNB Smart Chain (BSC) blockchain to evade traditional hosting blocks. Victims are lured via 'ClickFix' fake CAPTCHA prompts that trick users into executing PowerShell commands that download payloads from WebDAV shares.
The primary payload, Amatera (also known as ACR Stealer), serves as a modular delivery platform for secondary malware. Technical analysis revealed two distinct branches: one deploying ZigCryptoStealer via a NativeAOT loader and a Bring Your Own Vulnerable Driver (BYOVD) attack to terminate EDR processes, and another deploying an unauthorized NetSupport Manager instance for remote access. The use of blockchain-based dead-drop resolvers for C2 infrastructure highlights a growing trend in resilient, decentralized command-and-control architectures.
This campaign represents a significant risk to cryptocurrency assets and corporate credentials. The diversity of the attack chain—incorporating blockchain, WebDAV, module hollowing, and kernel-mode process termination—demonstrates a high level of operational maturity. Organizations should prioritize defending against fake browser-based verification prompts and monitoring for unusual WebDAV-related execution via rundll32.exe.
