Threat Summary
Two concurrent OTX pulses published on 2026-10-08 reveal a coordinated surge in cryptocurrency and credential theft operations targeting enterprise and consumer users alike. The primary campaign, attributed to UAT-10820, weaponizes the well-documented ClearFake/ClickFix social-engineering framework: compromised sites inject JavaScript via Cloudflare Workers, with payloads retrieved from the BNB Smart Chain using the "EtherHiding" technique. Victims are presented with fake Google CAPTCHA verification prompts that instruct them to execute commands which trigger WebDAV-based DLL side-loading, ultimately deploying Amatera stealer, ZigCryptoStealer, and the NetSupport Manager RAT for persistent remote access.
A second pulse documents 16 malicious Firefox extensions impersonating Rabby Wallet (typosquatted as "Raabby WaIIet") and OKX Wallet, intercepting seed phrases and private keys during wallet import flows and exfiltrating via Cloudflare Workers infrastructure.
Collectively, these campaigns share an objective — cryptocurrency and credential theft at scale — and share tradecraft: abuse of legitimate cloud infrastructure (Cloudflare Workers, WebDAV shares), blockchain-based payload staging to evade takedown, and social engineering that turns the user into the execution vector. Targeted countries include the US, Brazil, India, Ukraine, Egypt, and Indonesia, with government entities specifically in scope for UAT-10820.
Threat Actor / Malware Profile
UAT-10820 — ClearFake/ClickFix Cluster
Distribution method: Injected malicious JavaScript on compromised websites, served via Cloudflare Workers. The injection script is fetched from a smart contract on BNB Smart Chain (EtherHiding), making infrastructure resilient to domain takedowns. Fake Google CAPTCHA pages (e.g., verification.google lookalike domains) drive ClickFix-style copy/paste execution.
Payload behavior: The infection chain splits into two parallel paths, one loading a DLL named pf.ch (likely a truncated/obfuscated loader artifact). Final payloads:
- Amatera stealer — primary payload; harvests browser credentials, cookies, crypto wallets, FTP/VPN clients; exfiltrates over HTTPS to attacker C2 such as
leaguejazire.comandsmart.hugo-mapp.co. - ZigCryptoStealer — cryptocurrency-focused clipper/stealer targeting wallet addresses and clipboard contents.
- NetSupport Manager — legitimate RMM abused as a RAT, providing full interactive remote control and a durable foothold for follow-on activity.
C2 communication: HTTPS to attacker-controlled domains and Cloudflare-fronted infrastructure (hugo-mapp.co, unguidedfreewill.co hostnames). Blockchain RPC calls to BNB Smart Chain nodes are used for staging, not direct C2, complicating network-based attribution.
Persistence: NetSupport Manager installs as a service/startup entry; scheduled tasks and Run keys are commonly observed in ClearFake chains following WebDAV execution.
Anti-analysis: EtherHiding (payloads on immutable smart contracts), Cloudflare Workers to mask origin infrastructure, fake CAPTCHA gating that only detonates for interactive human sessions, and multi-stage DLL side-loading through legitimate signed binaries via WebDAV (\\...@SSL\DavWWWRoot paths).
Malicious Firefox Extensions Cluster
Distribution: Firefox Add-ons ecosystem / sideloaded extensions impersonating Rabby and OKX wallets, desktop utilities, and browser tools.
Payload behavior: Content scripts hook wallet import flows, capturing recovery phrases and private keys at the moment of entry. Exfiltration to Cloudflare Workers endpoints. Visual cloning includes deliberate homoglyph typosquatting (Raabby WaIIet with capital-I substitution).
IOC Analysis
The pulses contain 103 indicators across three types:
- Domains/hostnames (
leaguejazire.com,smart.hugo-mapp.co,paf.hugo-mapp.co,tnt.unguidedfreewill.co,verification.google): high-confidence C2 and lure infrastructure. Operationalize via DNS sinkhole, proxy block, and TLS SNI inspection. Noteverification.googleis a lookalike indicator, not legitimate Google infrastructure — treat any resolution as malicious. - FileHash-SHA256 (majority of both pulses): payload and extension artifacts. Load into EDR blocklists and retro-hunt via file hash reputation queries. For the Firefox extension hashes, search browser profile directories for unpacked extension folders matching these binaries.
- Tooling: Decode and pivot with VirusTotal/OTX alien lookups, URLScan.io for lure pages, and BscScan for EtherHiding contract analysis (look for smart contract read calls from browser processes). Network teams should alert on WebDAV (
PROPFIND,GETover UNC-style HTTP paths) to non-corporate destinations — this is rarely legitimate outside managed IT workflows.
Detection Engineering
---
title: ClearFake ClickFix WebDAV Execution Chain
description: Detects execution of payloads from WebDAV shares characteristic of the ClearFake/ClickFix UAT-10820 chain delivering Amatera stealer and NetSupport Manager
status: experimental
date: 2026/10/08
author: Security Arsenal Threat Intel
logsource:
category: process_creation
product: windows
detection:
selection_webdav:
CommandLine|contains:
- 'DavWWWRoot'
- '\\*@SSL\\'
- '\\*@SSL\DavWWWRoot\\'
selection_loader:
CommandLine|contains:
- 'rundll32'
- 'regsvr32'
- 'pf.ch'
condition: selection_webdav or (selection_loader and selection_webdav)
falsepositives:
- Legitimate corporate SharePoint WebDAV mappings (rare on endpoints)
level: high
tags:
- attack.execution
- attack.t1204
- attack.t1105
---
title: BNB Smart Chain EtherHiding Staging from Browser Process
description: Detects browser or scripting processes making RPC calls to BNB Smart Chain public nodes, consistent with EtherHiding payload retrieval used by UAT-10820
status: experimental
date: 2026/10/08
author: Security Arsenal Threat Intel
logsource:
category: network_connection
product: windows
detection:
selection_img:
Image|endswith:
- '\chrome.exe'
- '\firefox.exe'
- '\msedge.exe'
- '\powershell.exe'
- '\mshta.exe'
selection_dst:
DestinationHostname|contains:
- 'bsc-dataseed'
- 'binance.org'
- 'bnbchain'
- 'rpc.ankr.com'
condition: selection_img and selection_dst
falsepositives:
- Web3 developer workstations; crypto wallet desktop apps
level: medium
tags:
- attack.command_and_control
- attack.t1102
---
title: NetSupport Manager RAT Installation Artifacts
description: Detects installation or execution of NetSupport Manager client, abused by UAT-10820 as a persistence and remote access payload
status: experimental
date: 2026/10/08
author: Security Arsenal Threat Intel
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith:
- '\client32.exe'
- '\pcictlui.exe'
- '\NSM.exe'
CommandLine|contains:
- 'netsupport'
filter_paths:
Image|startswith:
- 'C:\Program Files\NetSupport\'
- 'C:\Program Files (x86)\NetSupport\'
condition: selection and not filter_paths
falsepositives:
- Managed IT environments using NetSupport legitimately (whitelist install paths)
level: high
tags:
- attack.command_and_control
- attack.t1219
// Hunt: ClearFake/Amatera C2 + WebDAV staging + wallet extension artifacts
let c2_domains = dynamic(["leaguejazire.com","hugo-mapp.co","unguidedfreewill.co","verification.google"]);
let net = DeviceNetworkEvents
| where TimeGenerated > ago(7d)
| where RemoteUrl has_any (c2_domains) or RemoteUrl contains "bsc-dataseed" or RemoteUrl contains "bnbchain"
| project TimeGenerated, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteUrl, RemoteIP;
let webdav = DeviceProcessEvents
| where TimeGenerated > ago(7d)
| where ProcessCommandLine has_any ("DavWWWRoot", "@SSL\\")
or ProcessCommandLine has "pf.ch"
or (FileName =~ "rundll32.exe" and ProcessCommandLine has "http")
| project TimeGenerated, DeviceName, FileName, ProcessCommandLine, InitiatingProcessFileName;
let netsupport = DeviceProcessEvents
| where TimeGenerated > ago(7d)
| where FileName in~ ("client32.exe","pcictlui.exe") or ProcessCommandLine has "netsupport"
| project TimeGenerated, DeviceName, FileName, ProcessCommandLine, FolderPath;
union net, webdav, netsupport
| sort by TimeGenerated desc
# ClearFake / Amatera / NetSupport endpoint IOC hunt — run elevated on suspect hosts
$ErrorActionPreference = 'SilentlyContinue'
$hashes = @(
'abd28aecb2d57660bcd9455333b84d289aa883eaf5cf15def1bf0feb35833aa2',
'93830d73ddf9665ae4d5665f1cebabd093646ed54356662e1b2a925bc2df681b',
'7504898b17a9ce05eb9209128bcd0fb67d675a70c8c64f6f624d08b47b2fe3af',
'7d9d7e80ed52350616be0215a7ded10aaeb9aaa64e34ff8af7f9177c8c855799',
'da447fe02e4577da97144a4d92b395078954fde1ff196746413837e1e4a20bcd',
'be246ca5cb1372394e0443df45454f88ca39eb4a8dcfc4a99cb8865100fb4897'
)
Write-Host "=== [1] NetSupport persistence artifacts ===" -ForegroundColor Cyan
Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run','HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run' |
Where-Object { $_.PSObject.Properties.Value -match 'netsupport|client32' }
Get-Service | Where-Object { $_.DisplayName -match 'NetSupport' } | Format-Table Name,Status,DisplayName
Get-ScheduledTask | Where-Object { $_.TaskPath -notlike '\Microsoft*' -and ($_.Actions.Execute -match 'client32|AppData|Temp') } | Format-List TaskName,TaskPath,Actions
Write-Host "=== [2] Known-bad hashes in common staging dirs ===" -ForegroundColor Cyan
$dirs = @("$env:TEMP","$env:LOCALAPPDATA","$env:APPDATA","$env:PUBLIC\Downloads","C:\ProgramData")
foreach ($d in $dirs) {
Get-ChildItem $d -Recurse -File -Depth 3 | ForEach-Object {
if ((Get-FileHash $_.FullName -Algorithm SHA256).Hash -in $hashes) {
Write-Host "[HIT] $($_.FullName)" -ForegroundColor Red
}
}
}
Write-Host "=== [3] Active connections to campaign C2 ===" -ForegroundColor Cyan
Get-NetTCPConnection -State Established | Where-Object {
$_.RemoteAddress -ne '127.0.0.1'
} | ForEach-Object {
$r = Resolve-DnsName $_.RemoteAddress -ErrorAction SilentlyContinue
if ($r.NameHost -match 'hugo-mapp|unguidedfreewill|leaguejazire|bsc-dataseed') {
$p = Get-Process -Id $_.OwningProcess
Write-Host "[C2] $($p.ProcessName) (PID $($_.OwningProcess)) -> $($r.NameHost) $($_.RemoteAddress)" -ForegroundColor Red
}
}
Write-Host "=== [4] WebDAV client traces ===" -ForegroundColor Cyan
Get-Service WebClient | Format-Table Name,Status,StartType
Get-ChildItem 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2' | Where-Object PSChildName -match 'DavWWWRoot' | Format-Table PSChildName
Write-Host "=== [5] Suspicious Firefox extensions ===" -ForegroundColor Cyan
Get-ChildItem "$env:APPDATA\Mozilla\Firefox\Profiles\*\extensions" -ErrorAction SilentlyContinue | ForEach-Object {
Write-Host $_.FullName
}
Get-ChildItem "$env:APPDATA\Mozilla\Firefox\Profiles" -Recurse -Filter 'manifest.json' -Depth 4 |
Select-String -Pattern 'raabby|wallet|okx' -List | ForEach-Object { Write-Host "[EXT-SUSPECT] $($_.Path)" -ForegroundColor Yellow }
Response Priorities
Immediate (0–4 hours)
- Block
leaguejazire.com,*.hugo-mapp.co,*.unguidedfreewill.co, and theverification.googlelookalike at DNS and proxy layers; add all 103 SHA256 hashes to EDR blocklists. - Alert on any WebDAV (
DavWWWRoot,@SSL) network traffic from user endpoints and on browser/scripting processes calling BNB Smart Chain RPC endpoints. - Sweep endpoints for
client32.exe/ NetSupport artifacts outside sanctioned install paths and for the 16 malicious Firefox extension hashes.
24 Hours
- Because Amatera and ZigCryptoStealer exfiltrate browser credentials, cookies, and session tokens, treat any host with a confirmed hit as a full identity compromise: force password resets, revoke active sessions and OAuth grants, and re-enroll MFA for affected users.
- Audit corporate crypto treasury or any users handling organizational wallets for unauthorized transactions; assume seed phrases entered during the exposure window are burned.
- Review Help Desk tickets and user reports for fake CAPTCHA / "verify you are human" prompts in the last 14 days to establish initial access timeline.
1 Week
- Disable or restrict the WebClient (WebDAV) service on endpoints where it is not business-required; block outbound SMB/WebDAV to the internet at the perimeter.
- Deploy browser extension governance: enforce allowlists for Firefox/Chrome extensions via enterprise policy, and block sideloading.
- Implement ClickFix-resistant controls: restrict user clipboard-to-terminal workflows where feasible, tune EDR for
rundll32/mshtaspawned by browsers, and add EtherHiding RPC domains to threat intel feeds. - Deliver targeted awareness on fake CAPTCHA lures — this campaign converts users into the installer, and technical controls alone will not close the gap.
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.