#clearfake — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #clearfake, aggregated by home.social.
-
A ClearFake WebDAV infection chain deployed Amatera malware. See how the ClearFake WebDAV infection chain drops crypto stealers on targets.
-
ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
Pulse ID: 6aa28af3eaecfaf6f4423f8f
Pulse Link: https://otx.alienvault.com/pulse/6aa28af3eaecfaf6f4423f8f
Pulse Author: Tr1sa111
Created: 2026-09-10 10:48:19Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ClearFake #CyberSecurity #InfoSec #NetSupport #NetSupportManager #OTX #OpenThreatExchange #bot #Tr1sa111
-
ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
Pulse ID: 6aa28af3eaecfaf6f4423f8f
Pulse Link: https://otx.alienvault.com/pulse/6aa28af3eaecfaf6f4423f8f
Pulse Author: Tr1sa111
Created: 2026-09-10 10:48:19Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ClearFake #CyberSecurity #InfoSec #NetSupport #NetSupportManager #OTX #OpenThreatExchange #bot #Tr1sa111
-
wrote up walking #ClearFake from injection to ClickFix with show 'n tell on Etherhiding. nothing terribly new, just how i manually walk it along with my first pass at digging at smart contract code.
https://rmceoin.github.io/malware-analysis/2026/09/09/clearfake.html
-
ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Indicators extracted from public reporting. Source: https://blog.talosintelligence.com/clearfake-webdav-infection-chain/
Pulse ID: 6aa17392921667b5acca2a74
Pulse Link: https://otx.alienvault.com/pulse/6aa17392921667b5acca2a74
Pulse Author: CyberHunter_NL
Created: 2026-09-09 14:56:18Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ClearFake #CyberSecurity #EDR #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Talos #bot #CyberHunter_NL
-
ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Indicators extracted from public reporting. Source: https://blog.talosintelligence.com/clearfake-webdav-infection-chain/
Pulse ID: 6aa17392921667b5acca2a74
Pulse Link: https://otx.alienvault.com/pulse/6aa17392921667b5acca2a74
Pulse Author: CyberHunter_NL
Created: 2026-09-09 14:56:18Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ClearFake #CyberSecurity #EDR #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Talos #bot #CyberHunter_NL
-
ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Indicators extracted from public reporting. Source: https://blog.talosintelligence.com/clearfake-webdav-infection-chain/
Pulse ID: 6aa17392921667b5acca2a74
Pulse Link: https://otx.alienvault.com/pulse/6aa17392921667b5acca2a74
Pulse Author: CyberHunter_NL
Created: 2026-09-09 14:56:18Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ClearFake #CyberSecurity #EDR #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Talos #bot #CyberHunter_NL
-
ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Indicators extracted from public reporting. Source: https://blog.talosintelligence.com/clearfake-webdav-infection-chain/
Pulse ID: 6aa17392921667b5acca2a74
Pulse Link: https://otx.alienvault.com/pulse/6aa17392921667b5acca2a74
Pulse Author: CyberHunter_NL
Created: 2026-09-09 14:56:18Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ClearFake #CyberSecurity #EDR #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Talos #bot #CyberHunter_NL
-
ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Indicators extracted from public reporting. Source: https://blog.talosintelligence.com/clearfake-webdav-infection-chain/
Pulse ID: 6aa17392921667b5acca2a74
Pulse Link: https://otx.alienvault.com/pulse/6aa17392921667b5acca2a74
Pulse Author: CyberHunter_NL
Created: 2026-09-09 14:56:18Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ClearFake #CyberSecurity #EDR #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Talos #bot #CyberHunter_NL
-
ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
An investigation revealed a sophisticated cryptocurrency and credential-stealing operation using Amatera stealer as the primary payload. The attack chain leverages Cloudflare Workers to inject JavaScript stored on BNB Smart Chain, presenting fake Google CAPTCHA prompts that lead to WebDAV-based DLL execution. Two parallel infection chains were identified, one loading through a DLL named 'pf.ch' and another through 'verification.google', both delivering Amatera stealer with different secondary payloads. The 'pf.ch' variant deployed ZigCryptoStealer via NativeAOT loader and a Go-based reverse proxy, while the 'verification.google' variant installed NetSupport Manager with C2 infrastructure in Russia. The operation affects numerous countries with primary focus on stealing cryptocurrency wallets, credentials from password managers, and various authentication data through extensive collection rules targeting over 400 applications.
Pulse ID: 6a9ffe054812bce013827753
Pulse Link: https://otx.alienvault.com/pulse/6a9ffe054812bce013827753
Pulse Author: AlienVault
Created: 2026-09-08 12:22:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CAPTCHA #ClearFake #Cloud #CyberSecurity #Google #InfoSec #Java #JavaScript #NetSupport #NetSupportManager #OTX #OpenThreatExchange #Password #Proxy #RAT #ReverseProxy #Russia #Word #bot #cryptocurrency #AlienVault
-
ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
An investigation revealed a sophisticated cryptocurrency and credential-stealing operation using Amatera stealer as the primary payload. The attack chain leverages Cloudflare Workers to inject JavaScript stored on BNB Smart Chain, presenting fake Google CAPTCHA prompts that lead to WebDAV-based DLL execution. Two parallel infection chains were identified, one loading through a DLL named 'pf.ch' and another through 'verification.google', both delivering Amatera stealer with different secondary payloads. The 'pf.ch' variant deployed ZigCryptoStealer via NativeAOT loader and a Go-based reverse proxy, while the 'verification.google' variant installed NetSupport Manager with C2 infrastructure in Russia. The operation affects numerous countries with primary focus on stealing cryptocurrency wallets, credentials from password managers, and various authentication data through extensive collection rules targeting over 400 applications.
Pulse ID: 6a9ffe054812bce013827753
Pulse Link: https://otx.alienvault.com/pulse/6a9ffe054812bce013827753
Pulse Author: AlienVault
Created: 2026-09-08 12:22:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CAPTCHA #ClearFake #Cloud #CyberSecurity #Google #InfoSec #Java #JavaScript #NetSupport #NetSupportManager #OTX #OpenThreatExchange #Password #Proxy #RAT #ReverseProxy #Russia #Word #bot #cryptocurrency #AlienVault
-
ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
An investigation revealed a sophisticated cryptocurrency and credential-stealing operation using Amatera stealer as the primary payload. The attack chain leverages Cloudflare Workers to inject JavaScript stored on BNB Smart Chain, presenting fake Google CAPTCHA prompts that lead to WebDAV-based DLL execution. Two parallel infection chains were identified, one loading through a DLL named 'pf.ch' and another through 'verification.google', both delivering Amatera stealer with different secondary payloads. The 'pf.ch' variant deployed ZigCryptoStealer via NativeAOT loader and a Go-based reverse proxy, while the 'verification.google' variant installed NetSupport Manager with C2 infrastructure in Russia. The operation affects numerous countries with primary focus on stealing cryptocurrency wallets, credentials from password managers, and various authentication data through extensive collection rules targeting over 400 applications.
Pulse ID: 6a9ffe054812bce013827753
Pulse Link: https://otx.alienvault.com/pulse/6a9ffe054812bce013827753
Pulse Author: AlienVault
Created: 2026-09-08 12:22:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CAPTCHA #ClearFake #Cloud #CyberSecurity #Google #InfoSec #Java #JavaScript #NetSupport #NetSupportManager #OTX #OpenThreatExchange #Password #Proxy #RAT #ReverseProxy #Russia #Word #bot #cryptocurrency #AlienVault
-
ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
An investigation revealed a sophisticated cryptocurrency and credential-stealing operation using Amatera stealer as the primary payload. The attack chain leverages Cloudflare Workers to inject JavaScript stored on BNB Smart Chain, presenting fake Google CAPTCHA prompts that lead to WebDAV-based DLL execution. Two parallel infection chains were identified, one loading through a DLL named 'pf.ch' and another through 'verification.google', both delivering Amatera stealer with different secondary payloads. The 'pf.ch' variant deployed ZigCryptoStealer via NativeAOT loader and a Go-based reverse proxy, while the 'verification.google' variant installed NetSupport Manager with C2 infrastructure in Russia. The operation affects numerous countries with primary focus on stealing cryptocurrency wallets, credentials from password managers, and various authentication data through extensive collection rules targeting over 400 applications.
Pulse ID: 6a9ffe054812bce013827753
Pulse Link: https://otx.alienvault.com/pulse/6a9ffe054812bce013827753
Pulse Author: AlienVault
Created: 2026-09-08 12:22:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CAPTCHA #ClearFake #Cloud #CyberSecurity #Google #InfoSec #Java #JavaScript #NetSupport #NetSupportManager #OTX #OpenThreatExchange #Password #Proxy #RAT #ReverseProxy #Russia #Word #bot #cryptocurrency #AlienVault
-
ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
An investigation revealed a sophisticated cryptocurrency and credential-stealing operation using Amatera stealer as the primary payload. The attack chain leverages Cloudflare Workers to inject JavaScript stored on BNB Smart Chain, presenting fake Google CAPTCHA prompts that lead to WebDAV-based DLL execution. Two parallel infection chains were identified, one loading through a DLL named 'pf.ch' and another through 'verification.google', both delivering Amatera stealer with different secondary payloads. The 'pf.ch' variant deployed ZigCryptoStealer via NativeAOT loader and a Go-based reverse proxy, while the 'verification.google' variant installed NetSupport Manager with C2 infrastructure in Russia. The operation affects numerous countries with primary focus on stealing cryptocurrency wallets, credentials from password managers, and various authentication data through extensive collection rules targeting over 400 applications.
Pulse ID: 6a9ffe054812bce013827753
Pulse Link: https://otx.alienvault.com/pulse/6a9ffe054812bce013827753
Pulse Author: AlienVault
Created: 2026-09-08 12:22:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CAPTCHA #ClearFake #Cloud #CyberSecurity #Google #InfoSec #Java #JavaScript #NetSupport #NetSupportManager #OTX #OpenThreatExchange #Password #Proxy #RAT #ReverseProxy #Russia #Word #bot #cryptocurrency #AlienVault