# UAT-10820 Uses WebDAV & Amatera Stealer for Credential Theft

> Russian threat actor UAT-10820 employs a complex WebDAV infection chain to deploy Amatera stealer, targeting credentials and cryptocurrency across a broad base.

- Published: 2026-10-02T03:11:48.000Z
- Severity: high
- Category: Threat Intel
- Tags: Credential Theft, Cryptocurrency, UAT 10820, Amatera, WebDAV
- Author: Runtime Rebel Intel
- Primary source: https://blog.talosintelligence.com/weve-got-one-word-for-it-and-its-usually-the-wrong-one/
- Canonical: https://runtimerebel.com/blog/uat-10820-uses-webdav-amatera-stealer-for-credential-theft

## Key points

- Russian actor UAT-10820 targets organizations with Amatera stealer via WebDAV, enabling credential and cryptocurrency theft.
- Affected systems: Victims using legitimate infrastructure like WebDAV are at risk; initial targets include Ukrainian government entities.
- Recommended remediation: Monitor WebDAV activity and rundll32.exe executions, enhance user education, and ensure memory scanning is configured.

The Russian [threat actor](/glossary#threat-actor) tracked as UAT-10820 is leveraging a sophisticated WebDAV infection chain to deploy the Amatera stealer and other secondary payloads, as detailed by [Cisco Talos](https://blog.talosintelligence.com/weve-got-one-word-for-it-and-its-usually-the-wrong-one/). This campaign, initially observed impacting a Ukrainian government organization, is assessed to be an opportunistic, broad-based operation primarily focused on stealing cryptocurrency and credentials rather than highly targeted attacks.

## UAT-10820 Campaign Overview

UAT-10820's activities demonstrate a creative approach to delivery mechanisms and evasion tactics. While the initial discovery involved a high-profile Ukrainian government entity, the modus operandi suggests a wider net. The goal is clear: financial gain through the exfiltration of sensitive information and digital assets. This shift to opportunistic targeting, even with advanced techniques, highlights the persistent threat posed by state-sponsored actors adapting their operations.

### Understanding the UAT-10820 WebDAV Infection Chain and Evasion Tactics

The core of the [attack vector](/glossary#attack-vector) relies on a complex WebDAV infection chain, a method that can bypass traditional security controls by abusing legitimate network protocols. Threat actors are employing bulletproof hosting by utilizing legitimate infrastructure like the BNB Smart Chain, making it difficult for defenders to block command and control ([C2](/glossary#c2)) communications. A critical evasion technique involves leveraging fake CAPTCHA prompts that instruct users to copy and paste commands, leading to the execution of malicious code. This [social engineering](/glossary#social-engineering) component is particularly dangerous as it exploits user trust in common verification processes.

Further compounding the threat, UAT-10820 deploys a vulnerable driver to terminate [Endpoint](/glossary#endpoint) Detection and Response ([EDR](/glossary#edr)) software. This move allows the attackers to operate with reduced detection risk, granting them an unfettered environment to establish [persistence](/glossary#persistence) and escalate privileges. This method of EDR circumvention is a significant concern, requiring defenders to implement layered security strategies beyond signature-based detection.

### Amatera Stealer and Secondary Payloads

Once the initial infection is established, the primary [payload](/glossary#payload) is the Amatera stealer. This [malware](/glossary#malware) is designed for efficient credential and cryptocurrency theft. A notable characteristic of Amatera is its ability to reside entirely in memory, making file-based detection challenging. This memory-resident nature underscores the importance of advanced memory forensics and scanning capabilities for effective Amatera stealer detection.

In addition to Amatera, the campaign also deploys secondary payloads such as ZigCryptoStealer, further emphasizing the focus on cryptocurrency exfiltration, and NetSupport Manager. The latter is a legitimate remote access tool that, when deployed by attackers, provides deep and persistent control over infected systems. This allows UAT-10820 to maintain a foothold, conduct further [reconnaissance](/glossary#reconnaissance), and exfiltrate data over extended periods, making it a severe threat for organizations focused on defending against credential-stealing operations.

## Actionable Recommendations for Defense

To mitigate the risks posed by UAT-10820's campaign, security teams should prioritize several key defensive measures:

*   **Monitor WebDAV Activity:** Implement strict monitoring for unusual WebDAV activity, particularly any attempts to download or execute files via this protocol. Anomalous access patterns should trigger immediate investigation.
*   **Scrutinize `rundll32.exe` Executions:** Pay close attention to the execution of disguised DLLs through `rundll32.exe` with suspicious ordinal calls. This is a common method for attackers to launch malicious code.
*   **Enhance User Education:** Conduct regular user training to educate personnel on the dangers of copying and pasting commands from unexpected or fake verification prompts. Emphasize vigilance against social engineering tactics.
*   **Configure Comprehensive Memory Scanning:** Ensure endpoint security solutions are configured to perform comprehensive memory scanning. Given Amatera's memory-resident nature, this capability is crucial for effective detection.
*   **Review Indicators of Compromise (IOCs):** Refer to the full blog post from Cisco Talos for a comprehensive list of IOCs to aid in detection and blocking.

**Related:** [Chinese-Speaking Operators Target Philippine Nuclear and Naval Assets](/blog/chinese-speaking-operators-target-philippine-nuclear-and-naval-assets), [ClearFake WebDAV Delivers Stealers & RATs to Ukrainian Gov](/blog/clearfake-webdav-delivers-stealers-rats-to-ukrainian-gov)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/uat-10820-uses-webdav-amatera-stealer-for-credential-theft
