Amatera
- Malware type
- credential-stealer
- Family
- Malware family
- Last IoC activity
- 2026-07-18 22:20:12
- Profile updated
- 2026-07-07 14:39:43
Targeted industries: financial-services technology-and-telecommunications
Context
Amatera is a stealer written in C++. It conducts anti-sandbox analysis before enumerating browsers, exfiltrating found cryptocurrency files/wallets and possibly credentials.
Detection coverage
- 1 YARA rules
Detection rules
- CAPE_Amatera (yara-rule)
Reports & references
- cip.gov.ua — Download (report)
- blackpointcyber.com — Novel Fake Captcha Chain Delivering Amatera Stealer (report)
- proofpoint.com — Amatera Stealer Rebranded Acr Stealer Improved Evasion Sophistication (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Amatera (report)
- github.com — Amatera%20Stealer%20V1.Md (report)
- bazaar.abuse.ch — 73Fd51D4A0959E5C5A82Db9Be0D765069D02A2B97F51F55F5D6422A7Bec01Caa (report)
- github.com — Amatera%20Shark.Exe.Md (report)