• bitcoinBitcoin (BTC) $ 90,159.00
  • ethereumEthereum (ETH) $ 3,124.96
  • tetherTether (USDT) $ 0.999642
  • xrpXRP (XRP) $ 2.03
  • bnbBNB (BNB) $ 876.87
  • usd-coinUSDC (USDC) $ 0.999911
  • staked-etherLido Staked Ether (STETH) $ 3,125.24
  • tronTRON (TRX) $ 0.288993
  • dogecoinDogecoin (DOGE) $ 0.141950
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.03
  • cardanoCardano (ADA) $ 0.393442
  • bitcoin-cashBitcoin Cash (BCH) $ 632.15
  • wrapped-stethWrapped stETH (WSTETH) $ 3,828.69
  • whitebitWhiteBIT Coin (WBT) $ 57.35
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 90,058.00
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 3,401.17
  • wrapped-eethWrapped eETH (WEETH) $ 3,395.28
  • usdsUSDS (USDS) $ 0.999752
  • chainlinkChainlink (LINK) $ 13.27
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999440
  • leo-tokenLEO Token (LEO) $ 9.26
  • wethWETH (WETH) $ 3,129.93
  • zcashZcash (ZEC) $ 492.69
  • moneroMonero (XMR) $ 429.24
  • stellarStellar (XLM) $ 0.223480
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 90,190.00
  • litecoinLitecoin (LTC) $ 82.45
  • suiSui (SUI) $ 1.66
  • ethena-usdeEthena USDe (USDE) $ 0.999293
  • avalanche-2Avalanche (AVAX) $ 13.84
  • hyperliquidHyperliquid (HYPE) $ 24.61
  • canton-networkCanton (CC) $ 0.149239
  • hedera-hashgraphHedera (HBAR) $ 0.121453
  • shiba-inuShiba Inu (SHIB) $ 0.000008
  • usdt0USDT0 (USDT0) $ 0.999229
  • susdssUSDS (SUSDS) $ 1.08
  • the-open-networkToncoin (TON) $ 1.82
  • daiDai (DAI) $ 0.999470
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.154867
  • uniswapUniswap (UNI) $ 6.09
  • crypto-com-chainCronos (CRO) $ 0.099062
  • paypal-usdPayPal USD (PYUSD) $ 0.999961
  • polkadotPolkadot (DOT) $ 2.17
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.21
  • usd1-wlfiUSD1 (USD1) $ 1.00
  • mantleMantle (MNT) $ 1.02
  • rainRain (RAIN) $ 0.008075
  • memecoreMemeCore (M) $ 1.52
  • pepePepe (PEPE) $ 0.000006
  • aaveAave (AAVE) $ 165.01
  • bitget-tokenBitget Token (BGB) $ 3.54
  • bittensorBittensor (TAO) $ 250.43
  • okbOKB (OKB) $ 113.94
  • tether-goldTether Gold (XAUT) $ 4,345.85
  • nearNEAR Protocol (NEAR) $ 1.69
  • falcon-financeFalcon USD (USDF) $ 0.997114
  • ethereum-classicEthereum Classic (ETC) $ 12.61
  • jito-staked-solJito Staked SOL (JITOSOL) $ 165.98
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,126.51
  • ethenaEthena (ENA) $ 0.237781
  • aster-2Aster (ASTER) $ 0.756734
  • pi-networkPi Network (PI) $ 0.212560
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • internet-computerInternet Computer (ICP) $ 3.17
  • solanaSolana (SOL) $ 132.59
  • hash-2Provenance Blockchain (HASH) $ 0.031142
  • pax-goldPAX Gold (PAXG) $ 4,339.06
  • htx-daoHTX DAO (HTX) $ 0.000002
  • hashnote-usycCircle USYC (USYC) $ 1.11
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.67
  • global-dollarGlobal Dollar (USDG) $ 0.999741
  • midnight-3Midnight (NIGHT) $ 0.090359
  • worldcoin-wldWorldcoin (WLD) $ 0.556067
  • kucoin-sharesKuCoin (KCS) $ 11.05
  • skySky (SKY) $ 0.063529
  • aptosAptos (APT) $ 1.89
  • binance-staked-solBinance Staked SOL (BNSOL) $ 144.60
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.14
  • ripple-usdRipple USD (RLUSD) $ 1.00
  • pump-funPump.fun (PUMP) $ 0.002277
  • ondo-financeOndo (ONDO) $ 0.425209
  • bfusdBFUSD (BFUSD) $ 0.999319
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,611.24
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999700
  • wbnbWrapped BNB (WBNB) $ 878.62
  • gatechain-tokenGate (GT) $ 10.58
  • kaspaKaspa (KAS) $ 0.045736
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.113838
  • arbitrumArbitrum (ARB) $ 0.207968
  • quant-networkQuant (QNT) $ 80.11
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,319.42
  • algorandAlgorand (ALGO) $ 0.126952
  • filecoinFilecoin (FIL) $ 1.53
  • cosmosCosmos Hub (ATOM) $ 2.18
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.02
  • bridged-wrapped-lido-staked-ether-scrollBridged Wrapped Lido Staked Ether (Scroll) (WSTETH) $ 3,824.28
  • vechainVeChain (VET) $ 0.011800
  • official-trumpOfficial Trump (TRUMP) $ 5.07
  • ignition-fbtcFunction FBTC (FBTC) $ 90,652.00
  • xdce-crowd-saleXDC Network (XDC) $ 0.051803
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 90,181.00
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 89,909.00
  • flare-networksFlare (FLR) $ 0.011243
  • nexoNEXO (NEXO) $ 0.922979
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 3,332.39
  • usddUSDD (USDD) $ 0.999744
  • usdtbUSDtb (USDTB) $ 0.999394
  • ousgOUSG (OUSG) $ 113.85
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.94
  • bonkBonk (BONK) $ 0.000009
  • render-tokenRender (RENDER) $ 1.54
  • sei-networkSei (SEI) $ 0.122845
  • wrappedm-by-m0WrappedM by M^0 (WM) $ 0.998171
  • myx-financeMYX Finance (MYX) $ 4.00
  • story-2Story (IP) $ 2.17
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999700
  • beldexBeldex (BDX) $ 0.095219
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 90,081.00
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,389.56
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • clbtcclBTC (CLBTC) $ 91,138.00
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,341.12
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.11
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.010813
  • lighterLighter (LIT) $ 2.70
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.01
  • jupiter-exchange-solanaJupiter (JUP) $ 0.209418
  • usdaiUSDai (USDAI) $ 1.00
  • wrapped-flareWrapped Flare (WFLR) $ 0.011245
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 3,296.77
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999748
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 153.94
  • morphoMorpho (MORPHO) $ 1.14
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,128.50
  • optimismOptimism (OP) $ 0.305241
  • curve-dao-tokenCurve DAO (CRV) $ 0.405075
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 24.82
  • tezosTezos (XTZ) $ 0.527492
  • c8ntinuumc8ntinuum (CTM) $ 0.128978
  • usual-usdUsual USD (USD0) $ 0.991120
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.23
  • dashDash (DASH) $ 43.18
  • tbtctBTC (TBTC) $ 90,130.00
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.228658
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,130.14
  • lido-daoLido DAO (LDO) $ 0.621606
  • spx6900SPX6900 (SPX) $ 0.557801
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.788565
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.999392
  • blockstackStacks (STX) $ 0.277826
  • ether-fiEther.fi (ETHFI) $ 0.771723
  • aerodrome-financeAerodrome Finance (AERO) $ 0.551911
  • gtethGTETH (GTETH) $ 3,130.26
  • ghoGHO (GHO) $ 0.999464
  • true-usdTrueUSD (TUSD) $ 0.998420
  • injective-protocolInjective (INJ) $ 4.91
  • flokiFLOKI (FLOKI) $ 0.000049
  • fasttokenFasttoken (FTN) $ 1.09
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 3,376.73
  • stader-ethxStader ETHx (ETHX) $ 3,372.01
  • msolMarinade Staked SOL (MSOL) $ 178.84
  • celestiaCelestia (TIA) $ 0.525595
  • chilizChiliz (CHZ) $ 0.044297
  • doublezeroDoubleZero (2Z) $ 0.126930
  • starknetStarknet (STRK) $ 0.086550
  • wrapped-apecoinWrapped ApeCoin (WAPE) $ 0.215948
  • newton-projectAB (AB) $ 0.004518
  • syrupMaple Finance (SYRUP) $ 0.367387
  • swethSwell Ethereum (SWETH) $ 3,473.09
  • sbtc-2sBTC (SBTC) $ 89,735.00
  • usdbUSDB (USDB) $ 0.997388
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,500.15
  • iotaIOTA (IOTA) $ 0.095166
  • plasmaPlasma (XPL) $ 0.194344
  • bittorrentBitTorrent (BTT) $ 0.00000041
  • the-graphThe Graph (GRT) $ 0.037165
  • conflux-tokenConflux (CFX) $ 0.076652
  • staked-aaveStaked Aave (STKAAVE) $ 164.08
  • ethereum-name-serviceEthereum Name Service (ENS) $ 10.25
  • justJUST (JST) $ 0.039125
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.11
  • telcoinTelcoin (TEL) $ 0.004042
  • pendlePendle (PENDLE) $ 2.22
  • sun-tokenSun Token (SUN) $ 0.019561
  • pippinpippin (PIPPIN) $ 0.372745
  • trust-wallet-tokenTrust Wallet (TWT) $ 0.888008
  • bitcoin-svBitcoin SV (BSV) $ 18.39
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.141960
  • pyth-networkPyth Network (PYTH) $ 0.063277
  • euro-coinEURC (EURC) $ 1.17
  • gnosisGnosis (GNO) $ 137.00
  • olympusOlympus (OHM) $ 21.85
  • apenftAINFT (NFT) $ 0.00000036
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 90,226.00
  • kaiaKaia (KAIA) $ 0.059127
  • cap-usdCap USD (CUSD) $ 1.00
  • benqi-liquid-staked-avaxBENQI Liquid Staked AVAX (SAVAX) $ 17.18
  • crvusdcrvUSD (CRVUSD) $ 0.999534
  • kinesis-goldKinesis Gold (KAU) $ 141.55
  • fartcoinFartcoin (FARTCOIN) $ 0.333049

Hackers target crypto wallets, browser data in fake reCAPTCHA pop-up campaign

0 36

Hackers target crypto wallets, browser data in fake reCAPTCHA pop-up campaign

Cybersecurity group eSentire has uncovered the use of fake CAPTCHA-style pop-ups to trick victims into deploying credential-harvesting malware, Amatera Stealer, and NETSupport RAT by abusing a method known as ClickFix.

eSentire’s Threat Response Unit (TRU) has been tracking an escalation in campaigns abusing ClickFix to gain initial access to targeted systems in November. According to the TRU, threat actors use the method to socially engineer victims into running malicious commands manually through the Windows Run prompt.

Once executed, those commands launch an infection chain that ends with the deployment of Amatera Stealer and NetSupport RAT, both legitimate remote monitoring tools that have been repurposed by cybercriminals for unauthorized remote access.

ClickFix campaign uses reCAPTCHA to sneak malware in

Per eSentire’s research published last Thursday, hackers are luring victims using fake websites and pop-ups that look like “security checks,” including fraudulent reCAPTCHA verification boxes and counterfeit Cloudflare Turnstile pages.

The deceptive interfaces prompt users to “fix” a supposed issue, with the instructions causing them to execute harmful commands without seeing the risks. Once the initial command is run, Amatera Stealer is delivered first, followed by the installation of NetSupport Manager, which allows hackers to monitor and control the compromised machine as though they were physically present.

Amatera Stealer is not an entirely new threat but the latest evolution of ACR Stealer, also known as AcridRain. The earlier version first appeared as a malware-as-a-service product on hacker forums in 2024, which several users deployed through subscription packages.

Sales of ACR were paused in mid-2024 when its developer, known online as SheldIO, sold the malware’s source code. Despite the sale announcement, the group said it was “not the end” of its development. Researchers now believe Amatera is the direct successor to ACR, rebuilt with more capabilities and new evasion techniques.

Amatera, spotted by security auditing firm Proofpoint in June, is available on a subscription basis from $199 per month to $1,499 annually.

“Amatera provides threat actors with extensive data exfiltration capabilities targeting crypto-wallets, browsers, messaging applications, FTP clients, and email services. It employs advanced evasion strategies like WoW64 SysCalls to circumvent user-mode hooking mechanisms used by sandboxes, Anti-Virus solutions, and EDR products,” eSentire said.

The malware is written in C++ and is capable of harvesting saved passwords, card details, browsing histories, and files from browsers like Chrome, Brave, Edge, Opera, Firefox, and specialized platforms such as Tor Browser and Thunderbird.

Multi-stage Windows PowerShell loaders hiding malware

According to eSentire’s threat analysis, the Amatera’s infection process is built on several layers of obfuscated PowerShell commands.

TRU researchers saw one phase decrypting subsequent payloads using an XOR process on the string “AMSI_RESULT_NOT_DETECTED,” a term associated with Microsoft’s Anti-Malware Scan Interface. The loader’s developer could have selected the phrase intentionally to confuse researchers conducting dynamic analysis.

While Amatera is the most common payload delivered in these campaigns, eSentire also documented cases where the same loader was used to deploy other infostealers, including Lumma and Vidar. Some samples lacked configuration parameters needed to run multi-stage loaders, in which hackers chose to deploy NetSupport Manager directly instead.

eSentire and other security firms have documented email campaigns distributing Visual Basic Script files disguised as invoices. When opened, the files executed batch scripts that initiated PowerShell loaders delivering XWorm.

Other campaigns involved compromised websites that redirected visitors to fake Cloudflare verification pages, which mimic ClickFix prompts. This activity has been tied to an operation known by names including SmartApeSG, HANEYMANEY, and ZPHP, all coming with NetSupport RAT as their final payload.

Hackers had built fraudulent Booking.com websites that hosted counterfeit CAPTCHA checks, instructing users to open the Windows Run dialog and execute a command, and directly installing a credential-stealing script onto infected systems.

Some of the phishing campaigns connected to these malware deliveries are using a new phishing kit known as Cephas. Cephas, according to cybersecurity solutions firm Barracuda, uses an advanced obfuscation method that inserts invisible characters into the source code of phishing pages, difficult for automated scanners to detect.

“The kit obscures its code by creating random invisible characters within the source code that help it evade anti-phishing scanners and obstruct signature-based YARA rules from matching the exact phishing methods,” Barracuda wrote in its analysis last week.

Source

Leave A Reply

Your email address will not be published.