Executive Summary
In June 2025, a threat campaign tracked as 'EVALUSION' leveraged sophisticated ClickFix social engineering lures to distribute the Amatera Stealer and NetSupport RAT. Cybersecurity researchers observed the attackers primarily targeting organizations through crafted phishing emails and malicious web downloads, enticing victims to execute payloads. Once inside, Amatera Stealer—an evolution of previous AcridRain infostealer variants—exfiltrated credentials and system information, while NetSupport RAT enabled persistent remote control. This resulted in a significant compromise of sensitive data and elevated risks of follow-on attacks, including lateral movement and further intrusions across corporate networks.
This incident highlights the rapid professionalization and diversification of infostealer toolkits. The growing adoption of ClickFix social engineering and commodity remote access tools by organized threat actors magnifies data exposure and regulatory risks, especially as hybrid and multi-cloud attack surfaces expand.
Why This Matters Now
The proliferation of advanced infostealers like Amatera, combined with highly effective social engineering tactics such as ClickFix, represents a pressing threat to organizations relying on email and browser-driven workflows. Rapid exploitation cycles and widespread distribution make swift detection, segmentation, and data-centric security policies more urgent than ever.
Attack Path Analysis
The attack began with users deceived by ClickFix-driven phishing links, leading to initial device compromise and malware dropper execution. The threat actors then established persistence and potentially escalated privileges via local abuse or installing remote access tools. Next, lateral movement was likely attempted to pivot inside the environment and discover additional assets. With NetSupport RAT and Amatera Stealer operating, C2 channels were set up to receive attacker instructions and enable remote control. Critical information, credentials, and sensitive data were exfiltrated through covert channels controlled by the malware. The campaign concluded with data theft and the risk of further business disruption or extortion.
Kill Chain Progression
Initial Compromise
Description
Targets were lured via social engineering (ClickFix phishing), leading to execution of Amatera Stealer and NetSupport RAT malware on endpoints.
Related CVEs
CVE-2024-21412
CVSS 8.8A vulnerability in Microsoft Windows SmartScreen allows attackers to bypass security warnings, leading to potential execution of malicious code.
Affected Products:
Microsoft Windows – 10, 11
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Phishing: Spearphishing Attachment
User Execution: Malicious File
Remote Access Software
Input Capture: Keylogging
Screen Capture
Exfiltration Over C2 Channel
Impair Defenses: Disable or Modify Tools
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Malicious Software Protection
Control ID: 5.2.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 10
CISA ZTMM 2.0 – User Awareness and Training
Control ID: 1.2.2
NIS2 Directive – Incident Handling Procedures
Control ID: Art. 21(1)(d)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
EVALUSION ClickFix campaigns targeting Amatera Stealer pose critical data exfiltration risks requiring enhanced egress security and zero trust segmentation for sensitive financial data protection.
Health Care / Life Sciences
NetSupport RAT deployment through ClickFix tactics threatens HIPAA compliance, demanding strengthened threat detection capabilities and encrypted traffic controls for protected health information.
Information Technology/IT
IT sectors face elevated risks from ACR Stealer evolution requiring comprehensive multicloud visibility, anomaly detection, and kubernetes security measures against advanced persistent threats.
Government Administration
Government entities must implement inline IPS and cloud native security fabric solutions to counter EVALUSION campaigns targeting critical infrastructure and sensitive administrative systems.
Sources
- New EVALUSION ClickFix Campaign Delivers Amatera Stealer and NetSupport RAThttps://thehackernews.com/2025/11/new-evalusion-clickfix-campaign.htmlVerified
- EVALUSION Campaign Delivers Amatera Stealer and NetSupport RAThttps://www.esentire.com/blog/evalusion-campaign-delivers-amatera-stealer-and-netsupport-ratVerified
- Amatera Stealer, NetSupport RAT spread in ClickFix campaignhttps://www.scworld.com/brief/amatera-stealer-netsupport-rat-spread-in-clickfix-campaignVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Applying Zero Trust controls such as east-west segmentation, real-time anomaly detection, stringent egress controls, and continuous encrypted traffic inspection would have sharply limited both malware propagation and the chances for successful data exfiltration. Comprehensive visibility and inline enforcement offered by CNSF would have detected C2 activity, constrained lateral movement, and enforced least-privilege, severely disrupting the adversary's objectives.
Control: Cloud Firewall (ACF)
Mitigation: Malicious or unauthorized inbound connections are blocked at the network perimeter.
Control: Zero Trust Segmentation
Mitigation: Limits attacker's ability to leverage compromised credentials beyond their minimum scope.
Control: East-West Traffic Security
Mitigation: Lateral propagation attempts between workloads are blocked or detected.
Control: Inline IPS (Suricata)
Mitigation: Known C2 traffic signatures and suspicious communications are detected and blocked.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration attempts are detected and prevented at the network boundary.
Anomalous exfiltration or malware-driven impact is rapidly detected for incident response.
Impact at a Glance
Affected Business Functions
- Finance
- IT Operations
- Customer Support
Estimated downtime: 5 days
Estimated loss: $500,000
Potential exposure of sensitive customer data, including financial records and personal information, due to unauthorized access facilitated by the malware.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce zero trust segmentation and internal microsegmentation to restrict lateral attacker movement post initial compromise.
- • Deploy strict egress controls and inline IPS to rapidly detect and block outbound C2 and exfiltration attempts.
- • Implement continuous encrypted traffic inspection and anomaly-based threat detection across all cloud workloads.
- • Harden cloud firewall boundary policies to block initial access and reduce attack surface from email-borne threats.
- • Maintain comprehensive, real-time visibility and centralized security policy management to enable rapid response.



