An investigation revealed a sophisticated cryptocurrency and credential-stealing operation using Amatera stealer as the primary payload. The attack chain leverages Cloudflare Workers to inject JavaScript stored on BNB Smart Chain, presenting fake Google CAPTCHA prompts that lead to WebDAV-based DLL execution. Two parallel infection chains were identified, one loading through a DLL named 'pf.ch' and another through 'verification.google', both delivering Amatera stealer with different secondary payloads. The 'pf.ch' variant deployed ZigCryptoStealer via NativeAOT loader and a Go-based reverse proxy, while the 'verification.google' variant installed NetSupport Manager with C2 infrastructure in Russia. The operation affects numerous countries with primary focus on stealing cryptocurrency wallets, credentials from password managers, and various authentication data through extensive collection rules targeting over 400 applications.
Created: 2026-09-09
類似するPulseは見つかりませんでした。
このPulseに見つかったCVEはありません。