ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager

Executive Summary

Cisco Talos assessed that the attacks are not targeted at a specific organization but are part of a broader cryptocurrency and credential‑stealing operation. The infection chain, delivered via a compromised WebDAV server, deploys the Amatera stealer as the primary payload, along with ZigCryptoStealer and NetSupport Manager components.


Intelligence Metadata - Source Publisher: Cisco Talos - Published Date: 2026-09-08T10:01:07+00:00 - Category: research

Original Description: We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as the primary payload.

"Adversity has the effect of eliciting talents, which in prosperous circumstances would have lain dormant."

— Horace
Source: Cisco Talos