BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

ClickFix Malware Campaigns Deploy Amatera Stealer, NetSupport RAT

Emerging Malware Campaigns Deploy Amatera Stealer and NetSupport RAT Using ClickFix Social Engineering Technique

  • Malware operations are using the ClickFix social engineering method to spread Amatera Stealer and NetSupport RAT.
  • Amatera is an updated version of ACR Stealer available via subscription, offering extensive data theft with advanced evasion tactics.
  • The attack chain involves deceptive CAPTCHA verification through Windows Run commands launching PowerShell scripts and loading malware.
  • NetSupport RAT deployment depends on identifying valuable data or domain membership on the victim’s device.
  • Multiple phishing campaigns use varied malware delivery methods, including fake invoices, manipulated websites, and obfuscated phishing kits.

Cybersecurity experts identified ongoing malware campaigns exploiting the ClickFix social engineering technique to distribute two key threats: Amatera Stealer and NetSupport RAT. This activity, observed in November 2025, is monitored by eSentire under the label EVALUSION.

- Advertisement -

Amatera, first seen in June 2025, is a development from the ACR (“AcridRain”) Stealer malware, which ceased sales in July 2024. It is now sold via subscription ranging from approximately $199 per month to $1,499 annually. According to eSentire, Amatera enables threat actors to extract sensitive information from crypto wallets, browsers, messaging apps, FTP clients, and email services. It employs advanced evasion strategies, including WoW64 SysCalls, to bypass common Sandbox, antivirus, and endpoint detection systems.

The ClickFix method deceives victims into running harmful commands through the Windows Run dialog as part of a bogus CAPTCHA on a phishing page. This triggers a multi-step process where “mshta.exe” executes a PowerShell script that downloads a .NET Dynamic Link Library (DLL) from the MediaFire file Hosting service. This DLL, the Amatera Stealer payload, is obfuscated with PureCrypter—a C#-based tool also marketed as malware-as-a-service by an actor named PureCoder. Upon injection into the “MSBuild.exe” process, the stealer collects data and contacts a remote server, which may issue a PowerShell command to install NetSupport RAT.

eSentire noted that the PowerShell script checks if the target computer belongs to a domain or hosts potentially valuable files, such as cryptocurrency wallets. If neither condition is met, NetSupport RAT is not downloaded.

This pattern aligns with several other phishing efforts distributing various malware types. These include emails carrying Visual Basic Script attachments that pose as invoices to deliver XWorm through PowerShell loaders; compromised websites with malicious JavaScript redirecting visitors to fake ClickFix pages mimicking Cloudflare Turnstile CAPTCHA, installing NetSupport RAT as part of the SmartApeSG campaign; and counterfeit Booking.com sites deploying fake CAPTCHA prompts to execute malicious PowerShell commands launching credential stealers via the Windows Run dialog.

- Advertisement -

Further tactics involve spoofed emails simulating internal “email delivery” alerts to steal login credentials and phishing kits named Cephas and Tycoon 2FA directing users to malicious login pages. Barracuda’s analysis highlighted Cephas’s unique obfuscation method, which inserts random invisible characters into its code to evade anti-phishing detectors and disrupt signature-based detection systems, as detailed in their recent report.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

JetBrains: Cadence Users Must Rotate Credentials After Hack

JetBrains urges Cadence users to immediately revoke and rotate all credentials after attackers exploited...

Polish crypto veto override fails by 25 votes amid scandal

Polish lawmakers failed to override President Karol Nawrocki’s veto of crypto oversight legislation, falling...

Sonic V2.2 doubles smart contract size limits for developers

Sonic V2.2 doubles the maximum deployed contract size from 24 KiB to 48 KiB...

ByteDance Secures $29.6B Loan from 30 Banks for AI Push

TikTok parent ByteDance secured a $29.6 billion loan from nearly 30 Chinese and international...

Musk: Tesla IPO value was a thousandth of current value

Tesla stock fell roughly 6% on Friday after the Cybercab launch event in Austin...

Must Read

Top 9 VPNs That Accept Bitcoin And Crypto

CyberGhost | FastVPN | TorGuard | Private Internet Access | ExpressVPN | NordVPN | Private VPN | SurfShark | AirVPN | Why Buy VPN...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading