We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as the primary payload.
First seen on blog.talosintelligence.com
Jump to article: blog.talosintelligence.com/clearfake-webdav-infection-chain/
![]()

