Fake 'Verification' Pages Trick Users into Running Hidden Malware Loaders
Cisco Talos researchers have detailed a malicious campaign that tricks victims into executing hidden malware through fake verification pages. The attack begins when a user is lured into running a file disguised with names like "verification.google", which is actually a DLL launched via a Windows tool called rundll32.exe over a WebDAV network path. This technique lets attackers deliver malware while making the process look like a routine file execution rather than an obvious download.
Talos traced this activity, attributed to a group tracked as UAT-10820, to at least two similar delivery chains that ultimately install the Amatera stealer, ZigCryptoStealer and NetSupport Manager remote access tool. These chains appear connected to a broader wave of campaigns using fake game downloads, software cracks and other social engineering lures to spread Amatera, as separately reported by Malwarebytes and Blackpoint Cyber. While the exact infrastructure differs between campaigns, all rely on tricking users into interacting with a fake verification or download prompt that quietly triggers the infection.
This type of attack is dangerous because it relies on legitimate Windows features (like WebDAV and rundll32) rather than obvious malicious executables, making it harder for basic antivirus tools to catch. Businesses should be alert to suspicious "verification" pop-ups or prompts, especially those requesting unusual file executions or network paths.