Amatera
tool · tool:amatera single-source
Amatera, InstallFix campaign infostealer targeting browser credentials and e-wallets
Coverage
1
first 2026-05-07 → last 2026-07-17
Latest activity
2026-07-17
Microsoft documents two ClickFix-rooted ACR Stealer chains: WebDAV+EtherHiding and fileless…
Peak priority
notable
1 notable
Targets
·
no sector or region stated
Sources cited
1
1 hosts
Defender insights
What each entry about Amatera tells a defender to do, newest first.
Triage
Relationships explore in graph
Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.
succeeded by
- ACR StealerMicrosoft reports ACR Stealer is 'reportedly ... associated with the rebranding of Amatera Stealer', a hedged rebrand/successor assessment, not confirmed.
Story timeline
Hunting pivots
ATT&CK techniques (15 across 7 tactics)
15 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- ExecutionScheduled Task/Job: Scheduled Task · Command and Scripting Interpreter: PowerShell · Command and Scripting Interpreter: Python · User Execution: Malicious Copy and Paste
- PersistenceScheduled Task/Job: Scheduled Task
- Privilege EscalationScheduled Task/Job: Scheduled Task
- StealthObfuscated Files or Information · Obfuscated Files or Information: Steganography · Masquerading · Indicator Removal: Clear Command History · System Binary Proxy Execution: Mshta · System Binary Proxy Execution: Rundll32 · Reflective Code Loading
- Credential AccessCredentials from Password Stores: Credentials from Web Browsers
- CollectionData from Local System · Data Staged: Local Data Staging
- Command and ControlWeb Service: Dead Drop Resolver
Execution TA0002
T1053.005Scheduled Task/Job: Scheduled Task×1
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.
Evidence: 2026-07-17/microsoft-acr-stealer-two-clickfix-intrusion-chains · ATT&CK page ↗
T1059.001Command and Scripting Interpreter: PowerShell×1
Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the <code>Start-Process</code> cmdlet which can be used to run an executable and the <code>Invoke-Command</code> cmdlet which runs a command locally or on a remote computer (though administrator permissions are required to use PowerShell to connect to remote systems).
Evidence: 2026-07-17/microsoft-acr-stealer-two-clickfix-intrusion-chains · ATT&CK page ↗
T1059.006Command and Scripting Interpreter: Python×1
Adversaries may abuse Python commands and scripts for execution. Python is a very popular scripting/programming language, with capabilities to perform many functions. Python can be executed interactively from the command-line (via the <code>python.exe</code> interpreter) or via scripts (.py) that can be written and distributed to different systems. Python code can also be compiled into binary executables.
Evidence: 2026-07-17/microsoft-acr-stealer-two-clickfix-intrusion-chains · ATT&CK page ↗
T1204.004User Execution: Malicious Copy and Paste×1
An adversary may rely upon a user copying and pasting code in order to gain execution. Users may be subjected to social engineering to get them to copy and paste code directly into a Command and Scripting Interpreter. One such strategy is "ClickFix," in which adversaries present users with seemingly helpful solutions (such as prompts to fix errors or complete CAPTCHAs) that instead instruct the user to copy and paste malicious code.
Evidence: 2026-07-17/microsoft-acr-stealer-two-clickfix-intrusion-chains · ATT&CK page ↗
Persistence TA0003
T1053.005Scheduled Task/Job: Scheduled Task×1
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.
Evidence: 2026-07-17/microsoft-acr-stealer-two-clickfix-intrusion-chains · ATT&CK page ↗
Privilege Escalation TA0004
T1053.005Scheduled Task/Job: Scheduled Task×1
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.
Evidence: 2026-07-17/microsoft-acr-stealer-two-clickfix-intrusion-chains · ATT&CK page ↗
Stealth TA0005
T1027Obfuscated Files or Information×1
Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.
Evidence: 2026-07-17/microsoft-acr-stealer-two-clickfix-intrusion-chains · ATT&CK page ↗
T1027.003Obfuscated Files or Information: Steganography×1
Adversaries may use steganography techniques in order to prevent the detection of hidden information. Steganographic techniques can be used to hide data in digital media such as images, audio tracks, video clips, or text files.
Evidence: 2026-07-17/microsoft-acr-stealer-two-clickfix-intrusion-chains · ATT&CK page ↗
T1036Masquerading×1
Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools. Masquerading occurs when the name or location of an object, legitimate or malicious, is manipulated or abused for the sake of evading defenses and observation. This may include manipulating file metadata, tricking users into misidentifying the file type, and giving legitimate task or service names.
Evidence: 2026-07-17/microsoft-acr-stealer-two-clickfix-intrusion-chains · ATT&CK page ↗
T1070.003Indicator Removal: Clear Command History×1
In addition to clearing system logs, an adversary may clear the command history of a compromised account to conceal the actions undertaken during an intrusion. Various command interpreters keep track of the commands users type in their terminal so that users can retrace what they've done.
Evidence: 2026-07-17/microsoft-acr-stealer-two-clickfix-intrusion-chains · ATT&CK page ↗
T1218.005System Binary Proxy Execution: Mshta×1
Adversaries may abuse mshta.exe to proxy execution of malicious .hta files and Javascript or VBScript through a trusted Windows utility. There are several examples of different types of threats leveraging mshta.exe during initial compromise and for execution of code
Evidence: 2026-07-17/microsoft-acr-stealer-two-clickfix-intrusion-chains · ATT&CK page ↗
T1218.011System Binary Proxy Execution: Rundll32×1
Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly (i.e. Shared Modules), may avoid triggering security tools that may not monitor execution of the rundll32.exe process because of allowlists or false positives from normal operations. Rundll32.exe is commonly associated with executing DLL payloads (ex: <code>rundll32.exe {DLLname, DLLfunction}</code>).
Evidence: 2026-07-17/microsoft-acr-stealer-two-clickfix-intrusion-chains · ATT&CK page ↗
T1620Reflective Code Loading×1
Adversaries may reflectively load code into a process in order to conceal the execution of malicious payloads. Reflective loading involves allocating then executing payloads directly within the memory of the process, vice creating a thread or process backed by a file path on disk (e.g., Shared Modules).
Evidence: 2026-07-17/microsoft-acr-stealer-two-clickfix-intrusion-chains · ATT&CK page ↗
Credential Access TA0006
T1555.003Credentials from Password Stores: Credentials from Web Browsers×1
Adversaries may acquire credentials from web browsers by reading files specific to the target browser. Web browsers commonly save credentials such as website usernames and passwords so that they do not need to be entered manually in the future. Web browsers typically store the credentials in an encrypted format within a credential store; however, methods exist to extract plaintext credentials from web browsers.
Evidence: 2026-07-17/microsoft-acr-stealer-two-clickfix-intrusion-chains · ATT&CK page ↗
Collection TA0009
T1005Data from Local System×1
Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.
Evidence: 2026-07-17/microsoft-acr-stealer-two-clickfix-intrusion-chains · ATT&CK page ↗
T1074.001Data Staged: Local Data Staging×1
Adversaries may stage collected data in a central location or directory on the local system prior to Exfiltration. Data may be kept in separate files or combined into one file through techniques such as Archive Collected Data. Interactive command shells may be used, and common functionality within cmd and bash may be used to copy data into a staging location.
Evidence: 2026-07-17/microsoft-acr-stealer-two-clickfix-intrusion-chains · ATT&CK page ↗
Command and Control TA0011
T1102.001Web Service: Dead Drop Resolver×1
Adversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure. Adversaries may post content, known as a dead drop resolver, on Web services with embedded (and often obfuscated/encoded) domains or IP addresses. Once infected, victims will reach out to and be redirected by these resolvers.
Evidence: 2026-07-17/microsoft-acr-stealer-two-clickfix-intrusion-chains · ATT&CK page ↗
Entries about Amatera (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- microsoft.com1 (100%)