MalwareTips News Fake CAPTCHA trick installs credential stealer through Windows WebDAV

News Now

Happening Now
Thread author
Verified
Sep 8, 2026
1
1
1
A ClearFake campaign is using fake Google CAPTCHA prompts to trick Windows users into running commands that install the Amatera information stealer. Cisco Talos found related activity at a Ukrainian government organization, but assesses with moderate confidence that the operation broadly targets cryptocurrency and credentials rather than one organization.


What users should watch for​

The investigated chain likely starts on a compromised website. Malicious browser code displays a fake verification checkbox, then tells a Windows visitor to open Run, paste clipboard contents and press Enter.

That pasted command reaches a remote WebDAV location and launches a disguised DLL. WebDAV is a Windows-supported way to access remote files, but here it is abused to execute the attacker's loader.

  • Do not paste commands supplied by a CAPTCHA or other website verification prompt.
  • If you already followed such instructions, disconnect the PC from the network and run a full security scan.
  • From a separate trusted device, change exposed passwords and review cryptocurrency accounts and wallets for unexpected activity.

Credentials and wallet data at risk​

Talos found that one Amatera configuration covered browser data, messaging apps, more than 100 desktop wallet locations, password managers, authenticators, email and FTP clients, VPN software, and remote-access tools.

The malware also searched common user folders for private keys, wallet backups, authentication data, password databases and certificate files. Talos said most collection rules focused on cryptocurrency information and credentials.

Different follow-on threats​

The two observed Amatera builds received different follow-on tasks from their command-and-control servers. One branch installed cryptocurrency-stealing and proxy capabilities, while the branch seen at the Ukrainian organization attempted to install an unauthorized NetSupport Manager remote-access tool.

NetSupport Manager is legitimate administration software, but an unauthorized installation can give an attacker remote access. Talos assessed with moderate confidence that the branch using it was operated by a Russian threat actor, based on configuration pointing to a server at a Russia-based IP address.

Have you encountered a website verification prompt that asked you to paste a command into Windows Run or Terminal?
 
  • Like
Reactions: Morro