eSentire's EVALUSION Campaign Delivers Amatera Stealer and NetSupport RAT

K
Kristopher Hetzel
3 months ago
155 views
30 nodes

eSentire’s TRU found that attackers were using ClickFix in late 2025 to deliver Amatera Stealer and NetSupport RAT. Amatera is essentially a rebranded version of the ACR (AcridRain) Stealer, whose source code was sold in 2024. It enables wide-ranging data theft from browsers and crypto wallets to messaging and email apps, and includes advanced evasion techniques like WoW64 SysCalls to bypass common security defenses. Research from @YungBinary https://www.esentire.com/blog/evalusion-campaign-delivers-amatera-stealer-and-netsupport-rat

React Flow mini map
eSentire's EVALUSION Campaign Delivers Amatera Stealer and NetSupport RAT - FlowViz Gallery