Amatera (aka Amatera Stealer) is a malware-as-a-service (MaaS) information stealer assessed to be based on / have code overlap with ACR Stealer. It is distributed in multiple observed social-engineering campaigns, including “InstallFix” (a ClickFix-style tactic) using Google Search ads that lead to fake installation/documentation pages (e.g., impersonating Anthropic’s Claude Code) and instruct victims to copy/paste malicious install commands. On Windows, one infection chain uses the system utility mshta.exe to execute an HTML application that deploys Amatera. Another ClickFix variant uses fake CAPTCHA prompts to trick users into pasting a command into the Windows Run dialog; the command abuses the signed Microsoft Application Virtualization (App-V) script SyncAppvPublishingServer.vbs (run via wscript.exe) to proxy PowerShell execution through trusted components. The App-V chain includes anti-sandbox/anti-analysis checks (including stalling behavior), retrieves base64-encoded configuration from a public Google Calendar (ICS) event used as a dead-drop resolver, and stages additional in-memory PowerShell loaders. Later stages download PNG images from attacker-controlled domains/CDNs and extract an encrypted/compressed PowerShell payload via steganography (LSB), which is decrypted, GZip-decompressed, and executed in memory, culminating in native shellcode that maps and executes Amatera.
Capabilities described include harvesting browser data (including browser-stored credentials, cookies, and session tokens), collecting crypto-wallet information, collecting system information, and stealing data from the user folder. Exfiltration/C2 details mentioned include sending stolen data to a remote server at 144.124.235.102; in the App-V/ClickFix chain, Amatera also connects to a hardcoded IP to retrieve endpoint mappings and can receive additional binary payloads via HTTP POST. The App-V abuse implies a focus on enterprise-managed Windows systems where App-V is present/enabled (e.g., Windows Enterprise/Education and modern Windows Server).
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
Other indicator types observed in public reporting.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this malware family.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.