Last seven days
- First activity
- Aug 30, 2026
- Last activity
- Sep 6, 2026
- Feed role
- C2 / Distribution
- Host form
- 0 IP / 453 hostnames
Amatera (aka Amatera Stealer) is a malware-as-a-service (MaaS) information stealer assessed to be based on / have code overlap with ACR Stealer.
Profile source: Mallory opens in a new tabAmatera
Amatera (aka Amatera Stealer) is a malware-as-a-service (MaaS) information stealer assessed to be based on / have code overlap with ACR Stealer. It is distributed in multiple observed social-engineering campaigns, including โInstallFixโ (a ClickFix-style tactic) using Google Search ads that lead to fake installation/documentation pages (e.g., impersonating Anthropicโs Claude Code) and instruct victims to copy/paste malicious install commands. On Windows, one infection chain uses the system utility mshta.exe to execute an HTML application that deploys Amatera. Another ClickFix variant uses fake CAPTCHA prompts to trick users into pasting a command into the Windows Run dialog; the command abuses the signed Microsoft Application Virtualization (App-V) script SyncAppvPublishingServer.vbs (run via wscript.exe) to proxy PowerShell execution through trusted components. The App-V chain includes anti-sandbox/anti-analysis checks (including stalling behavior), retrieves base64-encoded configuration from a public Google Calendar (ICS) event used as a dead-drop resolver, and stages additional in-memory PowerShell loaders. Later stages download PNG images from attacker-controlled domains/CDNs and extract an encrypted/compressed PowerShell payload via steganography (LSB), which is decrypted, GZip-decompressed, and executed in memory, culminating in native shellcode that maps and executes Amatera.
Capabilities described include harvesting browser data (including browser-stored credentials, cookies, and session tokens), collecting crypto-wallet information, collecting system information, and stealing data from the user folder. Exfiltration/C2 details mentioned include sending stolen data to a remote server at 144.124.235.102; in the App-V/ClickFix chain, Amatera also connects to a hardcoded IP to retrieve endpoint mappings and can receive additional binary payloads via HTTP POST. The App-V abuse implies a focus on enterprise-managed Windows systems where App-V is present/enabled (e.g., Windows Enterprise/Education and modern Windows Server).
C2 tracking
Derp observations, rolling seven-day window
Samples
01f5f40337f6c6c869d958bd9349f30bb3244d9042ded405b9343f2d79f22d30 022041dae02695e50aeea8e44c8600e987a932a13fea17de991672f8231fe564 02d6f5b0885feae70fc5eec999a6ac50129ee934ccdbddf26bb49b87dddb9c9a 032f08dac0b612cfd5d10d3da2fb5faf4ba108078ea11abee38c22aa79a4f10e 08a94337bd741faf8c30a1b588987f27f885ff839d8b6aa78c74cd09c342919c 08d4ec4adae301178c98dbaa1bf8e357db0c2973bba5d00926a0226f7f6a56f0 09f7389484acf555732d1c337981c9ecd51e25bf55ec1098915320b26fa71988 126e4904e70ebb8d900b16f87ef71efeaf20fe7a2322077611eba56c342a9379 16665812d02084939d83c098d3742c8a49056046cd2dfa616c11c4c847868177 178a235014e5bfcd27c1c1d6ac223a02072dd94ba7f2b01e240e437ec0c4e314 Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.