Malware, Threat Intelligence

Amatera Stealer, NetSupport RAT spread in ClickFix campaign

reCAPTCHA on windows screen. Checkmark to prove that you are not robot.

Threat actors have exploited the ClickFix social engineering technique to distribute the Amatera Stealer and NetSupport RAT payloads as part of the new EVALUSION campaign, reports The Hacker News.

Intrusions commenced with lures aimed at enabling the execution of illicit commands using the Windows Run dialog, which triggered a reCAPTCHA verification check leading to the deployment of a PowerShell script that subsequently downloaded a PureCrypter-packed Amatera Stealer DLL, according to eSentire researchers.

After being injected into the "MSBuild.exe" process, Amatera Stealer proceeds with data gathering and external server communications for the retrieval and execution of NetSupport RAT, said researchers, who noted that NetSupport RAT is only downloaded if Amatera finds value within the targeted machine.

Such a discovery comes amid the emergence of increasingly sophisticated phishing campaigns, including those that have leveraged the Cephas and Tycoon 2FA phishing kits, with the former found by Barracuda researchers to have advanced obfuscation techniques.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds