PULSE NAME
Amatera Stealer: Rebranded ACR Stealer With Improved Evasion, Sophistication
WHITE PetrP.73 2025-06-23 Modified: 2025-06-23
45
IOCs
MEDIUM VOLUME
Proofpoint has identified Amatera Stealer, a new variant of the ACR Stealer, rebranded and marketed as malware-as-a-service (MaaS) with advanced features and sophisticated anti-analysis capabilities. This malware enhances its stealth by employing NTSockets for communication with its command and control server and utilizes complex HTTP requests that avoid traditional DNS resolution. Amatera Stealer is distributed through ClearFake, which injects malicious scripts into legitimate sites, using techniques such as EtherHiding and ClickFix to deceive users and extract sensitive information from web browsers, cryptocurrency wallets, and messaging applications while evading detection. The overarching development of Amatera Stealer highlights a significant evolution in the threat landscape posed by information stealers, particularly amid increased competition from other malware solutions.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
GrMsk Lumma ClickFix ClearFake ACR Amatera
Indicators of Compromise (5 / 45 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname URL
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 1b4a67d5fc078f87ab5574c970c297f4 MD5 of 120316ecaf06b76a564ce42e11f7074c52df6d79b85d3526c5b4e9f362d2f1c2 2025-06-23
FileHash-MD5 5751851c33b98c544d60038d6f3893e3 MD5 of 7d91a585583f4aa1a3ab3cb808d7bc351d6140b3ae1deeef9d51c6414c11baea 2025-06-23
FileHash-MD5 ddc0168342a8d1e263d778a65bb47088 MD5 of ad9ffd624e27070092ff18a10e33fa9e2784b2c75ac9ac4540fa81cf5bd84e55 2025-06-23
FileHash-MD5 df75806b466c937b58d121b07a8d9079 MD5 of 35eb93548a0c037d392f870c05e0e9fb1aeff3a5a505e1d4a087f7465ed1f6af 2025-06-23
FileHash-MD5 fec6e80f71f291006e96a9f7d759f964 MD5 of 2960d5f8a3d9b0a21d6b744092fe3089517ecf2e49169683f754bfe9800e3991 2025-06-23