ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
Executive Summary
Cisco Talos assessed that the attacks are not targeted at a specific organization but are part of a broader cryptocurrency and credential‑stealing operation. The infection chain, delivered via a compromised WebDAV server, deploys the Amatera stealer as the primary payload, along with ZigCryptoStealer and NetSupport Manager components.
Intelligence Metadata - Source Publisher: Cisco Talos - Published Date: 2026-09-08T10:01:07+00:00 - Category: research
Original Description: We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as the primary payload.
"Adversity has the effect of eliciting talents, which in prosperous circumstances would have lain dormant."
— Horace