Amatera

Malware type
credential-stealer
Family
Malware family
Last IoC activity
2026-07-18 22:20:12
Profile updated
2026-07-07 14:39:43

Targeted industries: financial-services technology-and-telecommunications

Context

Amatera is a stealer written in C++. It conducts anti-sandbox analysis before enumerating browsers, exfiltrating found cryptocurrency files/wallets and possibly credentials.

Detection coverage

  • 1 YARA rules

Detection rules

  • CAPE_Amatera (yara-rule)

Reports & references

  • cip.gov.ua — Download (report)
  • blackpointcyber.com — Novel Fake Captcha Chain Delivering Amatera Stealer (report)
  • proofpoint.com — Amatera Stealer Rebranded Acr Stealer Improved Evasion Sophistication (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Amatera (report)
  • github.com — Amatera%20Stealer%20V1.Md (report)
  • bazaar.abuse.ch — 73Fd51D4A0959E5C5A82Db9Be0D765069D02A2B97F51F55F5D6422A7Bec01Caa (report)
  • github.com — Amatera%20Shark.Exe.Md (report)

External references