Amatera Stealer — Malware Profile
Amatera Stealer is an information stealer written in C++ and sold as a malware-as-a-service, with subscription plans advertised from $199 per month to $1,499 for a year. Proofpoint assesses it as a rebranded and substantially upgraded successor to ACR Stealer: the ACR support channel on Telegram announced the suspension of ACR Stealer sales in July 2024, and the first public mentions and scans of the Amatera panel surfaced in December 2024. It steals browser cookies, web form data and profile/history data, files belonging to software cryptocurrency wallets, browser extension files for password managers and wallets, and files from common email clients, SSH/FTP connection-management software and messaging applications including Signal and WhatsApp. For evasion it conducts anti-sandbox analysis, resolves and executes Windows APIs dynamically through WoW64 syscalls to bypass user-mode hooking, and contacts its C2 using NTSockets, interfacing with the AFD device (\Device\Afd\Endpoint) directly rather than the Winsock library that many EDR and analysis tools rely on for visibility into HTTP requests. Proofpoint observed it distributed via ClearFake website injects using fake CAPTCHA and ClickFix social engineering in April and May 2025, and notes third-party reports of delivery through software cracks and fake software downloads.