Marthio Marthio
TechnologyCrypto

Hackers deploy Amatera stealer via fake CAPTCHA and WebDAV in multi-stage Ukraine campaign

Cisco Talos researchers detected a cybercriminal operation linking counterfeit Google verification pages, BNB Smart Chain smart contracts, and the Amatera credential thief targeting Ukrainian government infrastructure.

Cybercriminals have executed a sophisticated, multi-stage attack combining fake Google CAPTCHA prompts, WebDAV servers, and blockchain technology to deploy the Amatera information stealer. The operation was discovered by Cisco Talos researchers who identified unusual endpoint activity at a Ukrainian government organization in April 2026. An attacker disguised a remote file as verification.google and executed it using the 32-bit Windows rundll32.exe program while activating the WebClient service. Talos assessed with moderate confidence that the target was part of a broader cryptocurrency and credential theft campaign rather than specific to Ukraine, tracking the branch as UAT-10820. The chain began on compromised websites where a malicious Cloudflare Worker injected code to retrieve JavaScript stored in a BNB Smart Chain smart contract. This sequence triggered a counterfeit CAPTCHA page using ClickFix social engineering, instructing users to copy and paste commands that reached WebDAV locations and launched disguised DLL files. Analysts reconstructed an earlier infection chain by hunting for similar patterns involving a second loader named pf.ch.

CybercriminalCredential theftUkraineAmatera stealerCaptchaWebdavBnb smart chainCisco talosCloud infrastructureMalware