Cybersecurity Research

Fake 'Verification' Pages Trick Users into Running Hidden Malware Loaders

Cisco Talos · 8 Sept 2026
Key Takeaway Train staff to be suspicious of any "verification" prompt that asks them to run a file or click through an unexpected pop-up, and keep endpoint protection updated to detect unusual use of legitimate Windows tools like rundll32.exe.

Cisco Talos researchers have detailed a malicious campaign that tricks victims into executing hidden malware through fake verification pages. The attack begins when a user is lured into running a file disguised with names like "verification.google", which is actually a DLL launched via a Windows tool called rundll32.exe over a WebDAV network path. This technique lets attackers deliver malware while making the process look like a routine file execution rather than an obvious download.

Talos traced this activity, attributed to a group tracked as UAT-10820, to at least two similar delivery chains that ultimately install the Amatera stealer, ZigCryptoStealer and NetSupport Manager remote access tool. These chains appear connected to a broader wave of campaigns using fake game downloads, software cracks and other social engineering lures to spread Amatera, as separately reported by Malwarebytes and Blackpoint Cyber. While the exact infrastructure differs between campaigns, all rely on tricking users into interacting with a fake verification or download prompt that quietly triggers the infection.

This type of attack is dangerous because it relies on legitimate Windows features (like WebDAV and rundll32) rather than obvious malicious executables, making it harder for basic antivirus tools to catch. Businesses should be alert to suspicious "verification" pop-ups or prompts, especially those requesting unusual file executions or network paths.

Summarised by CISO AI from Cisco Talos. We link back to every original so you can read it yourself.