UAT-10820 is a Russian-speaking, financially motivated threat cluster tracked in connection with the “verification.google” branch of ClearFake-related ClickFix activity. The cluster was observed executing a WebDAV-hosted DLL loader at a Ukrainian government organization in April 2026; the activity was assessed as part of a broader, opportunistic credential- and cryptocurrency-theft operation rather than an intrusion directed exclusively at that organization. The infection chain uses compromised websites, malicious Cloudflare Workers, and blockchain-hosted staged content to present Windows users with fake Google CAPTCHA prompts. Victims are socially engineered into executing commands through the Windows Run dialog, resulting in remote DLL execution through rundll32. The verification.google loader employs API hashing, direct WoW64 system calls, and DLL hollowing before deploying Amatera. Amatera is configured to collect browser data, credentials, cryptocurrency-wallet material, messaging-application data, password-manager data, authenticator data, VPN and remote-access application data, and selected files. UAT-10820 activity also installed a concealed NetSupport Manager client for hands-on remote access and established user-logon persistence through a scheduled task. Cisco Talos assesses with moderate confidence that UAT-10820 is a Russian threat actor. The related ClearFake remote-loader ecosystem has also delivered cryptocurrency-stealing tooling, defense-impairment components, and reverse-proxy payloads, although the delivery-chain relationship between those branches and the verification.google activity was assessed with lower confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
36 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
9 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Russia-aligned activity cluster attributed to some ClickFix-oriented campaigns targeting Ukrainian government systems.
Cybercriminal actor associated with the verification.google infection chain. The campaign uses compromised websites, Cloudflare Worker JavaScript injection, EtherHiding, fake Google CAPTCHA/ClickFix lures, WebDAV-delivered DLL execution, and remote-access tooling to steal cryptocurrency and credentials in apparently opportunistic, non-targeted attacks.
Activity cluster designation for the ClearFake-associated remote-loader branch, which uses fake CAPTCHA ClickFix lures and WebDAV-based remote library execution; one branch ultimately installs an unauthorized remote-access client.
A named activity cluster associated with ClearFake's remote-loader branch, using fake CAPTCHA ClickFix lures and WebDAV-hosted DLL execution to deploy secondary payloads, including remote-access capability.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.