Amatera Stealer is a Windows information stealer that fingerprints compromised hosts, captures screenshots, and decrypts stored browser credentials. It communicates with command-and-control infrastructure to receive collection instructions and can download additional payloads. Observed deployments execute the stealer in memory, reducing exposure to conventional file-based detection. Its command-and-control communications can use direct-IP TLS connections with misleading server-name and HTTP host values that impersonate legitimate services, obscuring malicious traffic in network telemetry. Some attack chains use a public publishing page as a dead-drop resolver to locate command-and-control infrastructure.
Amatera is distributed through ClickFix social engineering and malvertising. ClearFake campaigns deliver it through compromised websites, malicious Cloudflare Workers, blockchain-hosted staging instructions using EtherHiding, and fake CAPTCHA prompts that persuade Windows users to execute commands. These chains abuse WebDAV and ordinal-based DLL execution, with loaders using reflective loading or DLL hollowing to deploy Amatera in memory. PasteSwitch campaigns have also delivered it through fraudulent software advertisements and copied-command lures, using mshta and heavily obfuscated PowerShell stages that include AMSI bypassing and scheduled-task persistence.
Amatera has appeared in ClearFake activity tracked as UAT-10820, including an intrusion observed at a Ukrainian government organization, although the broader activity was assessed as opportunistic credential and cryptocurrency theft rather than exclusive targeting of that organization. Associated infection chains have deployed separate follow-on tools, including ZigCryptoStealer, a Go reverse TCP proxy, and NetSupport Manager.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"The DLL payload initiates a multi-stage process to drop Amatera Stealer."
In late April 2026, eSentire's Threat Response Unit (TRU) intercepted an attempted delivery of Amatera Stealer within a customer environment in the Finance industry. Amatera Stealer is a rebranded version of ACR (AcridRain) Stealer, a C++ based information stealer previously marketed as Malware-as-a-Service (MaaS) on underground forums by the threat actor SheldIO.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
One Windows attack chain led to creation of a task in Task Scheduler.
On Windows, the attackers used mshta and PowerShell; one chain launched the 32-bit version of PowerShell.
The sites instructed visitors to open Terminal on their Mac or, on Windows, the Run dialog or PowerShell, and paste in a command. This is the hallmark of a growing social engineering technique known as ClickFix.
Some ads directed users to convincing HBO lookalike sites that claimed to offer a native HBO Max app for macOS or a promotional download.
A subsequent PowerShell chain, obfuscated using arithmetic fog, dead loops, opaque predicates, base64, repeating-key XOR, rolling decoding and in-memory PE loading...
Users who clicked on these advertisements would be met with brand-spoofing websites displaying ClickFix-style download instructions.
The official HBO Max Reddit account was reportedly compromised and used in a malvertising campaign... The compromised account published 108 advertisements... promoting fake downloads.
The stealer could disguise communications with its command-and-control infrastructure as connections to Facebook.
The stealer used TLS SNI spoofing to disguise its C2 communications as connections to the Facebook website...
The adversary used a page hosted on the legitimate Telegra.ph publishing platform to conceal the location of its C2 server. This technique, known as a C2 dead-drop resolver...
329 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
94 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as another information-stealer family commonly observed among Gen users. No technical capabilities or direct connection to Warden Stealer are established.
Information-stealer family mentioned only as a prevalence comparison with Warden Stealer.
Named only as another highly prevalent infostealer in the reporting vendor's user base. No specific capabilities or operational connections to Warden Stealer are described.
Information stealer used as the primary payload in two attack chains. One chain used a Telegra.ph C2 dead-drop resolver; blocking the resolver page prevents Amatera from finding its C2 server, receiving collection instructions, or downloading additional payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.