AmateraStealer
AmateraStealer is an information-stealing malware family observed as part of a broader multi-family cybercriminal distribution ecosystem. Breakglass Intelligence reporting cited it alongside ACRStealer, SectopRAT, and NetSupport RAT as sharing infrastructure, delivery mechanisms, and operational patterns, and described the operator as running a multi-family stealer network. High-confidence reporting links AmateraStealer infrastructure to the ALTAWK/DGTLS-MNT bulletproof hosting cluster in Amsterdam, including infrastructure at 77.91.96.205. The same hosting environment was also associated with NetSupport RAT deployments and BrowserWare ClickFix campaigns. Reporting further states that ACRStealer delivery mechanisms included AmateraStealer, indicating it functioned as one of several loaders or distribution paths within the ecosystem. No additional malware-internal capabilities, infection chain details, or family-specific indicators beyond the shared infrastructure and ecosystem overlap were directly provided in the source content.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Techniques & procedures
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Resource Development
2 techniques
Resource Development
Initial Access
3 techniques
Initial Access
Execution
4 techniques
Execution
Stage 2: The PowerShell Vector (vocals.ps1) ... The dropper forces execution into 32-bit mode via SysWOW64 ... It then XOR-decrypts an embedded .NET assembly
MITRE ATT&CK Mapping ... Execution Native API T1106 ntdll.dll NtCreateThreadEx / NtAllocateVirtualMemory
Privilege Escalation
1 technique
Privilege Escalation
Stealth
5 techniques
Stealth
MITRE ATT&CK Mapping ... Defense Evasion Obfuscated Files T1027 3-layer encryption: XOR -> AES-256-CBC -> RC4
MITRE ATT&CK Mapping ... Defense Evasion Masquerading T1036 Trojanized legitimate RAM Booster installer
Calls NtAllocateVirtualMemory to allocate RWX memory in the current process ... Calls NtCreateThreadEx to spawn a thread executing the shellcode
Credential Access
2 techniques
Credential Access
Discovery
1 technique
Discovery
Collection
1 technique
Collection
Command and Control
3 techniques
Command and Control
MITRE ATT&CK Mapping ... Command and Control Application Layer Protocol: HTTPS T1071.001 HTTPS C2 on port 443
IOCs tracked for this family
44 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A stealer family named as part of the same multi-family stealer ecosystem sharing infrastructure and delivery patterns with SectopRAT.
Stealer malware described as part of ACRStealer's broader distribution ecosystem and infrastructure overlap, acting as a cross-family delivery partner with shared infrastructure.
Information-stealing malware previously associated with the same ALTAWK/DGTLS-MNT infrastructure cluster.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.