home.social

#clearfake — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #clearfake, aggregated by home.social.

  1. ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager

    Pulse ID: 6aa28af3eaecfaf6f4423f8f
    Pulse Link: otx.alienvault.com/pulse/6aa28
    Pulse Author: Tr1sa111
    Created: 2026-09-10 10:48:19

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ClearFake #CyberSecurity #InfoSec #NetSupport #NetSupportManager #OTX #OpenThreatExchange #bot #Tr1sa111

  2. ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager

    Pulse ID: 6aa28af3eaecfaf6f4423f8f
    Pulse Link: otx.alienvault.com/pulse/6aa28
    Pulse Author: Tr1sa111
    Created: 2026-09-10 10:48:19

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ClearFake #CyberSecurity #InfoSec #NetSupport #NetSupportManager #OTX #OpenThreatExchange #bot #Tr1sa111

  3. wrote up walking #ClearFake from injection to ClickFix with show 'n tell on Etherhiding.  nothing terribly new, just how i manually walk it along with my first pass at digging at smart contract code.

    rmceoin.github.io/malware-anal

  4. ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools

    Indicators extracted from public reporting. Source: blog.talosintelligence.com/cle

    Pulse ID: 6aa17392921667b5acca2a74
    Pulse Link: otx.alienvault.com/pulse/6aa17
    Pulse Author: CyberHunter_NL
    Created: 2026-09-09 14:56:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ClearFake #CyberSecurity #EDR #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Talos #bot #CyberHunter_NL

  5. ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools

    Indicators extracted from public reporting. Source: blog.talosintelligence.com/cle

    Pulse ID: 6aa17392921667b5acca2a74
    Pulse Link: otx.alienvault.com/pulse/6aa17
    Pulse Author: CyberHunter_NL
    Created: 2026-09-09 14:56:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ClearFake #CyberSecurity #EDR #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Talos #bot #CyberHunter_NL

  6. ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools

    Indicators extracted from public reporting. Source: blog.talosintelligence.com/cle

    Pulse ID: 6aa17392921667b5acca2a74
    Pulse Link: otx.alienvault.com/pulse/6aa17
    Pulse Author: CyberHunter_NL
    Created: 2026-09-09 14:56:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ClearFake #CyberSecurity #EDR #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Talos #bot #CyberHunter_NL

  7. ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools

    Indicators extracted from public reporting. Source: blog.talosintelligence.com/cle

    Pulse ID: 6aa17392921667b5acca2a74
    Pulse Link: otx.alienvault.com/pulse/6aa17
    Pulse Author: CyberHunter_NL
    Created: 2026-09-09 14:56:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ClearFake #CyberSecurity #EDR #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Talos #bot #CyberHunter_NL

  8. ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools

    Indicators extracted from public reporting. Source: blog.talosintelligence.com/cle

    Pulse ID: 6aa17392921667b5acca2a74
    Pulse Link: otx.alienvault.com/pulse/6aa17
    Pulse Author: CyberHunter_NL
    Created: 2026-09-09 14:56:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ClearFake #CyberSecurity #EDR #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Talos #bot #CyberHunter_NL

  9. ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager

    An investigation revealed a sophisticated cryptocurrency and credential-stealing operation using Amatera stealer as the primary payload. The attack chain leverages Cloudflare Workers to inject JavaScript stored on BNB Smart Chain, presenting fake Google CAPTCHA prompts that lead to WebDAV-based DLL execution. Two parallel infection chains were identified, one loading through a DLL named 'pf.ch' and another through 'verification.google', both delivering Amatera stealer with different secondary payloads. The 'pf.ch' variant deployed ZigCryptoStealer via NativeAOT loader and a Go-based reverse proxy, while the 'verification.google' variant installed NetSupport Manager with C2 infrastructure in Russia. The operation affects numerous countries with primary focus on stealing cryptocurrency wallets, credentials from password managers, and various authentication data through extensive collection rules targeting over 400 applications.

    Pulse ID: 6a9ffe054812bce013827753
    Pulse Link: otx.alienvault.com/pulse/6a9ff
    Pulse Author: AlienVault
    Created: 2026-09-08 12:22:29

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CAPTCHA #ClearFake #Cloud #CyberSecurity #Google #InfoSec #Java #JavaScript #NetSupport #NetSupportManager #OTX #OpenThreatExchange #Password #Proxy #RAT #ReverseProxy #Russia #Word #bot #cryptocurrency #AlienVault

  10. ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager

    An investigation revealed a sophisticated cryptocurrency and credential-stealing operation using Amatera stealer as the primary payload. The attack chain leverages Cloudflare Workers to inject JavaScript stored on BNB Smart Chain, presenting fake Google CAPTCHA prompts that lead to WebDAV-based DLL execution. Two parallel infection chains were identified, one loading through a DLL named 'pf.ch' and another through 'verification.google', both delivering Amatera stealer with different secondary payloads. The 'pf.ch' variant deployed ZigCryptoStealer via NativeAOT loader and a Go-based reverse proxy, while the 'verification.google' variant installed NetSupport Manager with C2 infrastructure in Russia. The operation affects numerous countries with primary focus on stealing cryptocurrency wallets, credentials from password managers, and various authentication data through extensive collection rules targeting over 400 applications.

    Pulse ID: 6a9ffe054812bce013827753
    Pulse Link: otx.alienvault.com/pulse/6a9ff
    Pulse Author: AlienVault
    Created: 2026-09-08 12:22:29

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CAPTCHA #ClearFake #Cloud #CyberSecurity #Google #InfoSec #Java #JavaScript #NetSupport #NetSupportManager #OTX #OpenThreatExchange #Password #Proxy #RAT #ReverseProxy #Russia #Word #bot #cryptocurrency #AlienVault

  11. ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager

    An investigation revealed a sophisticated cryptocurrency and credential-stealing operation using Amatera stealer as the primary payload. The attack chain leverages Cloudflare Workers to inject JavaScript stored on BNB Smart Chain, presenting fake Google CAPTCHA prompts that lead to WebDAV-based DLL execution. Two parallel infection chains were identified, one loading through a DLL named 'pf.ch' and another through 'verification.google', both delivering Amatera stealer with different secondary payloads. The 'pf.ch' variant deployed ZigCryptoStealer via NativeAOT loader and a Go-based reverse proxy, while the 'verification.google' variant installed NetSupport Manager with C2 infrastructure in Russia. The operation affects numerous countries with primary focus on stealing cryptocurrency wallets, credentials from password managers, and various authentication data through extensive collection rules targeting over 400 applications.

    Pulse ID: 6a9ffe054812bce013827753
    Pulse Link: otx.alienvault.com/pulse/6a9ff
    Pulse Author: AlienVault
    Created: 2026-09-08 12:22:29

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CAPTCHA #ClearFake #Cloud #CyberSecurity #Google #InfoSec #Java #JavaScript #NetSupport #NetSupportManager #OTX #OpenThreatExchange #Password #Proxy #RAT #ReverseProxy #Russia #Word #bot #cryptocurrency #AlienVault

  12. ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager

    An investigation revealed a sophisticated cryptocurrency and credential-stealing operation using Amatera stealer as the primary payload. The attack chain leverages Cloudflare Workers to inject JavaScript stored on BNB Smart Chain, presenting fake Google CAPTCHA prompts that lead to WebDAV-based DLL execution. Two parallel infection chains were identified, one loading through a DLL named 'pf.ch' and another through 'verification.google', both delivering Amatera stealer with different secondary payloads. The 'pf.ch' variant deployed ZigCryptoStealer via NativeAOT loader and a Go-based reverse proxy, while the 'verification.google' variant installed NetSupport Manager with C2 infrastructure in Russia. The operation affects numerous countries with primary focus on stealing cryptocurrency wallets, credentials from password managers, and various authentication data through extensive collection rules targeting over 400 applications.

    Pulse ID: 6a9ffe054812bce013827753
    Pulse Link: otx.alienvault.com/pulse/6a9ff
    Pulse Author: AlienVault
    Created: 2026-09-08 12:22:29

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CAPTCHA #ClearFake #Cloud #CyberSecurity #Google #InfoSec #Java #JavaScript #NetSupport #NetSupportManager #OTX #OpenThreatExchange #Password #Proxy #RAT #ReverseProxy #Russia #Word #bot #cryptocurrency #AlienVault

  13. ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager

    An investigation revealed a sophisticated cryptocurrency and credential-stealing operation using Amatera stealer as the primary payload. The attack chain leverages Cloudflare Workers to inject JavaScript stored on BNB Smart Chain, presenting fake Google CAPTCHA prompts that lead to WebDAV-based DLL execution. Two parallel infection chains were identified, one loading through a DLL named 'pf.ch' and another through 'verification.google', both delivering Amatera stealer with different secondary payloads. The 'pf.ch' variant deployed ZigCryptoStealer via NativeAOT loader and a Go-based reverse proxy, while the 'verification.google' variant installed NetSupport Manager with C2 infrastructure in Russia. The operation affects numerous countries with primary focus on stealing cryptocurrency wallets, credentials from password managers, and various authentication data through extensive collection rules targeting over 400 applications.

    Pulse ID: 6a9ffe054812bce013827753
    Pulse Link: otx.alienvault.com/pulse/6a9ff
    Pulse Author: AlienVault
    Created: 2026-09-08 12:22:29

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CAPTCHA #ClearFake #Cloud #CyberSecurity #Google #InfoSec #Java #JavaScript #NetSupport #NetSupportManager #OTX #OpenThreatExchange #Password #Proxy #RAT #ReverseProxy #Russia #Word #bot #cryptocurrency #AlienVault