ctipilot.chSwitzerland · Europe · Public sector

InstallFix — malvertising campaign distributing Amatera infostealer via fake AI tool install pages

campaign · campaign:installfix

Coverage timeline
1
first 2026-05-07 → last 2026-05-07
Briefs
1
1 distinct
Sources cited
3
3 hosts
Sections touched
1
research
Co-occurring entities
0
no co-occurrence

Story timeline

  1. 2026-05-07CTI Daily Brief — 2026-05-07
    researchFirst coverage. Active since March 2026; malvertised Google Ads for AI coding tool searches; Netherlands government sector explicitly targeted; polyglot ZIP/HTA delivery; AMSI bypass via RC4-decrypted strings.

Where this entity is cited

  • research1

Source distribution

  • malwarebytes.com1 (33%)
  • pushsecurity.com1 (33%)
  • trendmicro.com1 (33%)

Items in briefs about InstallFix — malvertising campaign distributing Amatera infostealer via fake AI tool install pages

No parsed item heading or body matches this entity yet. Items match by exact CVE id (for CVE entities), by lead-segment substring of the title in the item heading or body, or by a distinctive anchor token from the title appearing in the item heading. Coverage that lives inside a broader section (no per-item heading) is captured by the Story timeline above.