The Containment Era is here. →Explore

Executive Summary

In June 2025, a threat campaign tracked as 'EVALUSION' leveraged sophisticated ClickFix social engineering lures to distribute the Amatera Stealer and NetSupport RAT. Cybersecurity researchers observed the attackers primarily targeting organizations through crafted phishing emails and malicious web downloads, enticing victims to execute payloads. Once inside, Amatera Stealer—an evolution of previous AcridRain infostealer variants—exfiltrated credentials and system information, while NetSupport RAT enabled persistent remote control. This resulted in a significant compromise of sensitive data and elevated risks of follow-on attacks, including lateral movement and further intrusions across corporate networks.

This incident highlights the rapid professionalization and diversification of infostealer toolkits. The growing adoption of ClickFix social engineering and commodity remote access tools by organized threat actors magnifies data exposure and regulatory risks, especially as hybrid and multi-cloud attack surfaces expand.

Why This Matters Now

The proliferation of advanced infostealers like Amatera, combined with highly effective social engineering tactics such as ClickFix, represents a pressing threat to organizations relying on email and browser-driven workflows. Rapid exploitation cycles and widespread distribution make swift detection, segmentation, and data-centric security policies more urgent than ever.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The attack revealed weaknesses in egress policy enforcement, endpoint segmentation, and encrypted traffic monitoring, highlighting gaps against regulations such as HIPAA 164.312(e)(1) and PCI 4.0 DS-5.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Applying Zero Trust controls such as east-west segmentation, real-time anomaly detection, stringent egress controls, and continuous encrypted traffic inspection would have sharply limited both malware propagation and the chances for successful data exfiltration. Comprehensive visibility and inline enforcement offered by CNSF would have detected C2 activity, constrained lateral movement, and enforced least-privilege, severely disrupting the adversary's objectives.

Initial Compromise

Control: Cloud Firewall (ACF)

Mitigation: Malicious or unauthorized inbound connections are blocked at the network perimeter.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Limits attacker's ability to leverage compromised credentials beyond their minimum scope.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Lateral propagation attempts between workloads are blocked or detected.

Command & Control

Control: Inline IPS (Suricata)

Mitigation: Known C2 traffic signatures and suspicious communications are detected and blocked.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Data exfiltration attempts are detected and prevented at the network boundary.

Impact (Mitigations)

Anomalous exfiltration or malware-driven impact is rapidly detected for incident response.

Impact at a Glance

Affected Business Functions

  • Finance
  • IT Operations
  • Customer Support
Operational Disruption

Estimated downtime: 5 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Potential exposure of sensitive customer data, including financial records and personal information, due to unauthorized access facilitated by the malware.

Recommended Actions

  • Enforce zero trust segmentation and internal microsegmentation to restrict lateral attacker movement post initial compromise.
  • Deploy strict egress controls and inline IPS to rapidly detect and block outbound C2 and exfiltration attempts.
  • Implement continuous encrypted traffic inspection and anomaly-based threat detection across all cloud workloads.
  • Harden cloud firewall boundary policies to block initial access and reduce attack surface from email-borne threats.
  • Maintain comprehensive, real-time visibility and centralized security policy management to enable rapid response.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image