The Russian threat actor tracked as UAT-10820 is leveraging a sophisticated WebDAV infection chain to deploy the Amatera stealer and other secondary payloads, as detailed by Cisco Talos. This campaign, initially observed impacting a Ukrainian government organization, is assessed to be an opportunistic, broad-based operation primarily focused on stealing cryptocurrency and credentials rather than highly targeted attacks.
UAT-10820 Campaign Overview
UAT-10820’s activities demonstrate a creative approach to delivery mechanisms and evasion tactics. While the initial discovery involved a high-profile Ukrainian government entity, the modus operandi suggests a wider net. The goal is clear: financial gain through the exfiltration of sensitive information and digital assets. This shift to opportunistic targeting, even with advanced techniques, highlights the persistent threat posed by state-sponsored actors adapting their operations.
Understanding the UAT-10820 WebDAV Infection Chain and Evasion Tactics
The core of the attack vector relies on a complex WebDAV infection chain, a method that can bypass traditional security controls by abusing legitimate network protocols. Threat actors are employing bulletproof hosting by utilizing legitimate infrastructure like the BNB Smart Chain, making it difficult for defenders to block command and control (C2) communications. A critical evasion technique involves leveraging fake CAPTCHA prompts that instruct users to copy and paste commands, leading to the execution of malicious code. This social engineering component is particularly dangerous as it exploits user trust in common verification processes.
Further compounding the threat, UAT-10820 deploys a vulnerable driver to terminate Endpoint Detection and Response (EDR) software. This move allows the attackers to operate with reduced detection risk, granting them an unfettered environment to establish persistence and escalate privileges. This method of EDR circumvention is a significant concern, requiring defenders to implement layered security strategies beyond signature-based detection.
Amatera Stealer and Secondary Payloads
Once the initial infection is established, the primary payload is the Amatera stealer. This malware is designed for efficient credential and cryptocurrency theft. A notable characteristic of Amatera is its ability to reside entirely in memory, making file-based detection challenging. This memory-resident nature underscores the importance of advanced memory forensics and scanning capabilities for effective Amatera stealer detection.
In addition to Amatera, the campaign also deploys secondary payloads such as ZigCryptoStealer, further emphasizing the focus on cryptocurrency exfiltration, and NetSupport Manager. The latter is a legitimate remote access tool that, when deployed by attackers, provides deep and persistent control over infected systems. This allows UAT-10820 to maintain a foothold, conduct further reconnaissance, and exfiltrate data over extended periods, making it a severe threat for organizations focused on defending against credential-stealing operations.
Actionable Recommendations for Defense
To mitigate the risks posed by UAT-10820’s campaign, security teams should prioritize several key defensive measures:
- Monitor WebDAV Activity: Implement strict monitoring for unusual WebDAV activity, particularly any attempts to download or execute files via this protocol. Anomalous access patterns should trigger immediate investigation.
- Scrutinize
rundll32.exeExecutions: Pay close attention to the execution of disguised DLLs throughrundll32.exewith suspicious ordinal calls. This is a common method for attackers to launch malicious code. - Enhance User Education: Conduct regular user training to educate personnel on the dangers of copying and pasting commands from unexpected or fake verification prompts. Emphasize vigilance against social engineering tactics.
- Configure Comprehensive Memory Scanning: Ensure endpoint security solutions are configured to perform comprehensive memory scanning. Given Amatera’s memory-resident nature, this capability is crucial for effective detection.
- Review Indicators of Compromise (IOCs): Refer to the full blog post from Cisco Talos for a comprehensive list of IOCs to aid in detection and blocking.
Related: Chinese-Speaking Operators Target Philippine Nuclear and Naval Assets, ClearFake WebDAV Delivers Stealers & RATs to Ukrainian Gov