New Fake CAPTCHA Scam Abuses Microsoft Tools to Install Amatera Stealer
ID: ffa7675c-b92c-5c6d-8592-b7375aaf95b5
STIX ID: report--ffa7675c-b92c-5c6d-8592-b7375aaf95b5
Feed Name: HackRead
Blackpoint Cyber disclosed a fake CAPTCHA campaign that coerces users to run keyboard shortcuts and paste commands which invoke a legitimate Windows script (SyncAppvPublishingServer.vbs) to fetch and execute Amatera Stealer. The chain uses Google Calendar .ics files and PNG steganography to host instructions and payloads, and relies on living‑off‑the‑land binaries and clipboard checks to evade sandboxes, resulting in credential and browser data theft on vulnerable Windows 10/11 or Server systems with App‑V enabled.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
