Skip to content

Amatera

Amatera (aka Amatera Stealer) is a malware-as-a-service (MaaS) information stealer assessed to be based on / have code overlap with ACR Stealer.

Profile source: Mallory opens in a new tab

Amatera

Family profile

Amatera (aka Amatera Stealer) is a malware-as-a-service (MaaS) information stealer assessed to be based on / have code overlap with ACR Stealer. It is distributed in multiple observed social-engineering campaigns, including โ€œInstallFixโ€ (a ClickFix-style tactic) using Google Search ads that lead to fake installation/documentation pages (e.g., impersonating Anthropicโ€™s Claude Code) and instruct victims to copy/paste malicious install commands. On Windows, one infection chain uses the system utility mshta.exe to execute an HTML application that deploys Amatera. Another ClickFix variant uses fake CAPTCHA prompts to trick users into pasting a command into the Windows Run dialog; the command abuses the signed Microsoft Application Virtualization (App-V) script SyncAppvPublishingServer.vbs (run via wscript.exe) to proxy PowerShell execution through trusted components. The App-V chain includes anti-sandbox/anti-analysis checks (including stalling behavior), retrieves base64-encoded configuration from a public Google Calendar (ICS) event used as a dead-drop resolver, and stages additional in-memory PowerShell loaders. Later stages download PNG images from attacker-controlled domains/CDNs and extract an encrypted/compressed PowerShell payload via steganography (LSB), which is decrypted, GZip-decompressed, and executed in memory, culminating in native shellcode that maps and executes Amatera.

Capabilities described include harvesting browser data (including browser-stored credentials, cookies, and session tokens), collecting crypto-wallet information, collecting system information, and stealing data from the user folder. Exfiltration/C2 details mentioned include sending stolen data to a remote server at 144.124.235.102; in the App-V/ClickFix chain, Amatera also connects to a hardcoded IP to retrieve endpoint mappings and can receive additional binary payloads via HTTP POST. The App-V abuse implies a focus on enterprise-managed Windows systems where App-V is present/enabled (e.g., Windows Enterprise/Education and modern Windows Server).

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 30, 2026
Last activity
Sep 6, 2026
Feed role
C2 / Distribution
Host form
0 IP / 453 hostnames

Leading locations

  • US182
  • DE60
  • ES28
  • FR25
  • GB18
  • NL17
  • IT16
  • SG10
  • AU9
  • CH7
  • CY6
  • ZA6

Leading providers

  • Cloudflare, Inc.38
  • Oracle Corporation31
  • IONOS SE24
  • Grupo Loading Systems, S.L.23
  • DigitalOcean, LLC22
  • Google LLC17

Infrastructure traits

  • Hosting 442
  • Anycast 81
  • Proxy 1

Samples

Recent associated samples

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.