BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

ClickFix Malware Campaigns Deploy Amatera Stealer, NetSupport RAT

Emerging Malware Campaigns Deploy Amatera Stealer and NetSupport RAT Using ClickFix Social Engineering Technique

  • Malware operations are using the ClickFix social engineering method to spread Amatera Stealer and NetSupport RAT.
  • Amatera is an updated version of ACR Stealer available via subscription, offering extensive data theft with advanced evasion tactics.
  • The attack chain involves deceptive CAPTCHA verification through Windows Run commands launching PowerShell scripts and loading malware.
  • NetSupport RAT deployment depends on identifying valuable data or domain membership on the victim’s device.
  • Multiple phishing campaigns use varied malware delivery methods, including fake invoices, manipulated websites, and obfuscated phishing kits.

Cybersecurity experts identified ongoing malware campaigns exploiting the ClickFix social engineering technique to distribute two key threats: Amatera Stealer and NetSupport RAT. This activity, observed in November 2025, is monitored by eSentire under the label EVALUSION.

- Advertisement -

Amatera, first seen in June 2025, is a development from the ACR (“AcridRain”) Stealer malware, which ceased sales in July 2024. It is now sold via subscription ranging from approximately $199 per month to $1,499 annually. According to eSentire, Amatera enables threat actors to extract sensitive information from crypto wallets, browsers, messaging apps, FTP clients, and email services. It employs advanced evasion strategies, including WoW64 SysCalls, to bypass common Sandbox, antivirus, and endpoint detection systems.

The ClickFix method deceives victims into running harmful commands through the Windows Run dialog as part of a bogus CAPTCHA on a phishing page. This triggers a multi-step process where “mshta.exe” executes a PowerShell script that downloads a .NET Dynamic Link Library (DLL) from the MediaFire file Hosting service. This DLL, the Amatera Stealer payload, is obfuscated with PureCrypter—a C#-based tool also marketed as malware-as-a-service by an actor named PureCoder. Upon injection into the “MSBuild.exe” process, the stealer collects data and contacts a remote server, which may issue a PowerShell command to install NetSupport RAT.

eSentire noted that the PowerShell script checks if the target computer belongs to a domain or hosts potentially valuable files, such as cryptocurrency wallets. If neither condition is met, NetSupport RAT is not downloaded.

This pattern aligns with several other phishing efforts distributing various malware types. These include emails carrying Visual Basic Script attachments that pose as invoices to deliver XWorm through PowerShell loaders; compromised websites with malicious JavaScript redirecting visitors to fake ClickFix pages mimicking Cloudflare Turnstile CAPTCHA, installing NetSupport RAT as part of the SmartApeSG campaign; and counterfeit Booking.com sites deploying fake CAPTCHA prompts to execute malicious PowerShell commands launching credential stealers via the Windows Run dialog.

- Advertisement -

Further tactics involve spoofed emails simulating internal “email delivery” alerts to steal login credentials and phishing kits named Cephas and Tycoon 2FA directing users to malicious login pages. Barracuda’s analysis highlighted Cephas’s unique obfuscation method, which inserts random invisible characters into its code to evade anti-phishing detectors and disrupt signature-based detection systems, as detailed in their recent report.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

No charges against Justin Sun

The SEC has appointed David Woodcock as its new director of enforcement, effective May...

Chaos Malware Variant Now Targets Cloud Deployments

A new variant of the Chaos malware is now targeting misconfigured cloud deployments, expanding...

Trump Proposes US-Iran Joint Strait of Hormuz Toll

Former President Donald Trump proposed a potential joint venture with Iran to charge tolls...

Cloudflare Targets Quantum-Safe Platform by 2029

Cloudflare announced an accelerated plan to make its entire platform resistant to quantum computing...

Barclays Cuts Robinhood PT, ARK Buys $13M in HOOD

Barclays lowered Robinhood's price target to $89 and downgraded Coinbase to 'Underweight' on lower...

Must Read

Are Cryptocurrency Securities?

TL;DR - Cryptocurrencies are not typically considered securities, as they are decentralized digital assets that operate independently of any central authority or government. However,...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading