08-09-2026
ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
https://blog.talosintelligence.com/clearfake-webdav-infection-chain/
Report completeness: High
Actors/Campaigns:
Clickfake
Evalusion
Threats:
Amatera_stealer
Clearfake
Zigcrypto
Netsupportmanager_rat
Clickfix_technique
Etherhiding_technique
Dll_sideloading_technique
Dead_drop_technique
Hijackloader
Acr_stealer
Anydesk_tool
Yamux_tool
Byovd_technique
Iclickfix_tool
Victims:
Government
Industry:
Government
Geo:
Indonesia, Ukrainian, Egypt, Brazil, Russian, Ukraine, Russia, United states, India
ChatGPT TTPs:
do not use without manual checkT1027, T1027.002, T1036, T1053.005, T1055.002, T1055.012, T1059.001, T1059.004, T1059.007, T1071.001, have more...
IOCs:
File: 14
Coin: 3
Domain: 17
Url: 6
IP: 3
Hash: 22
Soft:
NativeAOT, RenPy, Microsoft App-V, Chrome, macOS, curl, Steam, Telegram, WhatsApp, KeePass, have more...
Algorithms:
sha256, xor, ecdh, lznt1, zip, chacha20-poly1305, base64
Functions:
GetEndpoints, setData
Win API:
AddVectoredExceptionHandler, GetUserNameExW, ZwTerminateProcess, LdrLoadDll, NtAllocateVirtualMemory, NtProtectVirtualMemory, NtFreeVirtualMemory, decompress, GetTickCount64, NtDelayExecution, have more...
Win Services:
WebClient
Languages:
rust, powershell, golang, javascript
Platforms:
x86
Links:
https://github.com/hashicorp/yamux