Skip to main content

Netskope Threat Labs details EtherHiding campaign that ends with Amatera password stealer

Companies mentioned

Netskope Threat Labs reports tracking a WordPress mass-compromise campaign that chains browser and Windows execution steps through a rogue must-use plugin, a persistent Service Worker, and a Base smart contract payload delivery method. The report matters to enterprise security leaders because it combines client-side control with multiple defense-evasion techniques to culminate in credential theft.

Research overview

The blog describes a campaign affecting hundreds of WordPress sites, where the initial compromise involves a rogue must-use plugin. Netskope Threat Labs states it has not seen a Service Worker resolve a payload from a smart contract before and attributes the discovery to how the multiple layers fit together.

Netskope Threat Labs says it reviewed the attack by peeling back nine layers, concluding that the design uses “no durable artifacts to act on, no file to hash, no server to seize, no download to inspect.”

Key findings

According to the blog, each stage is built to defeat a specific defense, and the overall flow is presented as a ladder. Netskope Threat Labs frames the combination of Service Worker persistence and on-chain payload retrieval as a key reason it investigated the chain further.

The blog’s described end result is the “Amatera password stealer,” which the report says calls home over DNS-over-HTTPS. It also lists additional techniques used within the chain, including EtherHiding on-chain payload delivery, fake reCAPTCHA interaction, and ClickFix.

Technical breakdown

The first layer is a compromised WordPress site that loads a rogue must-use plugin on every request, using the site context in which visitors already trust the domain. The blog says the next layer is a malicious Service Worker that persists in the browser and operates independently of the site’s server.

Netskope Threat Labs states the Service Worker intercepts page loads, deletes the Content-Security-Policy and content-length headers from HTML responses, and injects script behavior to carry the next stage. The blog then describes a Base smart contract that holds the payload labeled EtherHiding.

Operational impact

The blog says the on-chain delivery leads to a fake reCAPTCHA prompt intended to make the victim run a command by hand. It then describes a sequence involving an MP3/HTA polyglot and Windows execution behavior, followed by a scheduled task and a PowerShell stage that run filelessly with “AMSI blinded.”

The blog further describes an “Emmenhtal loader” paired with a steganographic image on a legitimate CDN and a reflective loader that does not write the payload to disk. It also lists additional mechanisms such as “mshta abuse,” a “fileless PowerShell stage,” and a disguised polyglot file that are used within the overall chain.

Overall, the Netskope Threat Labs blog portrays a multi-layer WordPress compromise that uses persistent browser infrastructure plus a Base smart contract to deliver a sequence of user-driven and fileless Windows stages culminating in Amatera credential theft over DNS-over-HTTPS. This “Blog Signals brief” is a fact-based summary of the vendor blog.

Source: netskope.com, by Vini Egerland.

Graph Connections

31st This is Netskope's 31st mention on Decision Insights this quarter, following coverage of its Netskope and Cybersecurity Insiders examine 72-hour evidence readiness in August.