logo

New Fake CAPTCHA Scam Abuses Microsoft Tools to Install Amatera Stealer

ID: ffa7675c-b92c-5c6d-8592-b7375aaf95b5

STIX ID: report--ffa7675c-b92c-5c6d-8592-b7375aaf95b5

Feed Name: HackRead

Threat Score
68/100

Date Published: 2026-01-26

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Blackpoint Cyber disclosed a fake CAPTCHA campaign that coerces users to run keyboard shortcuts and paste commands which invoke a legitimate Windows script (SyncAppvPublishingServer.vbs) to fetch and execute Amatera Stealer. The chain uses Google Calendar .ics files and PNG steganography to host instructions and payloads, and relies on living‑off‑the‑land binaries and clipboard checks to evade sandboxes, resulting in credential and browser data theft on vulnerable Windows 10/11 or Server systems with App‑V enabled.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.