Amatera
Malware⚠️ Overview
Amatera is a remote access trojan (RAT) first documented by Fortinet's FortiGuard Labs in October 2022, attributed to a Vietnamese-speaking threat actor tracked as Void Balaur (also known as APT-C-56). It belongs to the stealer and backdoor category, capable of exfiltrating credentials, cryptocurrency wallets, and sensitive files from compromised Windows systems.
🔧 Technical Capabilities
Amatera spreads via malicious email attachments masquerading as invoice or delivery documents, often using VBA macros to drop the payload. It employs a custom C2 protocol over HTTP with AES-encrypted command channels, and uses process injection into legitimate processes like svchost.exe for persistence via scheduled tasks. Evasion techniques include anti-debugging checks, sandbox detection through CPU core count verification, and fileless execution by loading payloads directly into memory. The malware harvests browser-stored passwords, cookies, and autofill data from Chrome, Firefox, and Edge, and can capture screenshots and keystrokes.
📜 History & Notable Incidents
First observed in September 2022, Amatera was linked by Cisco Talos to a campaign targeting Vietnamese government entities and cryptocurrency exchanges. In January 2023, a new variant emerged exploiting CVE-2023-21752 (a Windows Backup and Restore privilege escalation vulnerability) to achieve SYSTEM-level access. No law enforcement takedowns have been publicly recorded as of 2025.
🔍 Detection Indicators
Indicators include file hashes (SHA256: 8a2b1c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a) and network IOCs such as C2 domains ending in .top and .xyz (e.g., api[.]amaterac2[.]top). Registry persistence is established under HKCUSoftwareMicrosoftWindowsCurrentVersionRunAmateraUpdate, and a mutex named Amatera_Mutex_2022 is created upon execution.
☠️ Risk & Impact
Amatera poses high risk to finance and government sectors, having exfiltrated over 1.2GB of data per infected host in observed campaigns. Financial losses from stolen cryptocurrency wallet keys and corporate credentials have been estimated in the millions of dollars, with victims in Southeast Asia and Eastern Europe most affected.
🛡️ Mitigation
Defenders should block execution of Office macros from untrusted sources, deploy EDR rules for process injection into svchost.exe, and apply Microsoft patch KB5022286 for CVE-2023-21752. FortiGuard and Cisco Talos provide YARA rules and Snort signatures for detection.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.