ClearFake malware infects systems via WebDAV
ClearFake is a malware campaign that tricks users into opening a fake file share link, then steals data and encrypts files. Attackers use a feature called WebDAV to hide malicious files on shared folders, which can infect any system that opens them.
- Report priority
- Medium
How it works
- Attackers send users a fake link that looks like a shared folder.
- When a user clicks it, their device connects to a hidden WebDAV server.
- The server then drops a malicious file called Amatera onto the device.
- This file steals passwords and encrypts files without permission.
What to do
If you clicked a shared folder link in the last few days and noticed new files or strange behavior on your device, check your downloads folder for unknown files named Amatera or similar. If you see unfamiliar files or your files are encrypted, immediately disconnect from the internet, do not open any new files, and run a full antivirus scan.
Use a trusted security tool like Malwarebytes or Windows Defender to remove the malware. If files are encrypted, do not pay ransom, contact local law enforcement or a cybersecurity expert for help.
Technical details
A user receives an email with a link to a shared folder labeled 'Important Documents.' When they click the link, their device connects to a hidden WebDAV server. The server automatically downloads and runs Amatera malware, which begins stealing passwords and encrypting files on their system.
A ClearFake WebDAV infection chain deployed Amatera malware. See how the ClearFake WebDAV infection chain drops crypto stealers on targets.