The popular reaction to a fresh loader write-up is to hunt for a zero-day. You should hunt for a setting you never turned off. Cisco Talos’s ClearFake reporting this week shows stealers arriving through WebDAV, a Windows file-share client that most cybersecurity programs stopped budgeting attention for years ago. The lures need your users to treat a remote share as a folder. If your ingress model still starts with brute-force against a login page, you are watching the wrong door.

Cybersecurity Programs Still Treat WebDAV as a Relic

You probably killed FTP in a meeting. You may even have a network standard that says no legacy file protocols on the internet. Windows still ships WebDAV as the WebClient service, and it still turns a URL into something that looks like a folder. Attackers like that because the user experience is “open this document,” not “run this payload.”

Talos assesses with moderate confidence that the ClearFake activity is part of a cryptocurrency and credentials-stealing operation, with Amatera as the primary payload. That finding should change how you prioritize. Opportunistic stealers do not need your org chart. They need a client that will mount a hostile share and a user who will click through a lure that looks like a file server.

A firewall that is proud of TLS inspection can still pass this traffic, because WebDAV often rides HTTP on ports you already allow. Your proxy policy scores the browser. The operating system performs the mount after the click. Those are different trust decisions. Only one of them is in the change ticket you reviewed last quarter.

Cisco Talos threat spotlight artwork for a ClearFake WebDAV malware chain
Talos’s ClearFake write-up is a reminder that “file access” on Windows can be code execution with extra steps.

This is a bad look for stacks that spent three years arguing about browser isolation and then left a file-sharing client enabled for every laptop image. Cyber security teams talk about reducing the attack surface. WebDAV is the surface you forgot to put on the list. If mapped HTTP shares are not a documented business need, they are an unowned execution path.

A Mounted Share Is a Trusted Installer

Once the share is up, the rest of the chain is a business model you have seen before. Amatera harvests credentials and session material. ZigCryptoStealer goes after wallet-adjacent data. NetSupport Manager gives an operator a remote-control foothold when they want to stay. You already know what stealers do. They empty browsers, lift tokens, and raid the password stores your SSO rollout never fully replaced.

NetSupport is the detail that should rewrite the ticket, not a footnote. A “commodity stealer” alert can hide an interactive RAT. If your incident response runbook closes at “we found infostealer telemetry on one PC,” you will miss the operator who used that PC as a helpdesk. Treat remote-admin binaries that you did not deploy as confirmed intrusion, even when the first payload had a stealer name.

Google Threat Intelligence Group’s Q3 2026 AI Threat Tracker adds the part your playbooks have not timed for. Researchers, drawing on Mandiant engagements and live platform defenses, watched attackers move from one-off prompts toward workflows where AI systems handle several connected tasks: scanning, credential harvesting, troubleshooting failed steps. In Q2 2026, Mandiant investigated a financially motivated credential-theft campaign that ran for hours with that kind of stitching. ClearFake can still look like a classic loader. The people who buy the dumps will not stay that slow.

Illustration of an AI system involved in automated cyberattack workflows
Once a stealer lands, the follow-on harvest is getting less human and more automated. Your containment clock has to match that.

Threat detection that only watches impossible logins will see the account takeover after the wallet, the session cookie, and the VPN token are already gone. Defense here starts at the mount and the child process, not at the IdP dashboard. That is the operational meaning of defense in depth for this chain: stop the protocol, catch the execution, and assume stolen secrets are already in motion.

Kill the Protocol, Then Hunt Like You Were Breached

You do not need a new product family to cut this path. You need an inventory, a hard default, and a hunt that assumes the lure already worked somewhere. Do the immediate work in this order:

  1. Inventory where the Windows WebClient service is enabled, including golden images, VDI pools, jump boxes, and the one “legacy app” OU everyone is afraid to touch.
  2. Disable WebClient via policy everywhere mapped HTTP/WebDAV shares are not a written business requirement. If a line of business still needs them, pin that need to a named group and a named owner, not to “Domain Computers.”
  3. On user VLANs, block outbound WebDAV methods and known DAV URL patterns at the edge. HTTP on 443 is not automatically innocent when the request is PROPFIND from a laptop that never mounts shares.
  4. Tell staff, in one blunt paragraph, that “open this folder” and “your document is on this link” are execution events. Same handling as a macro. Same urgency as a USB drop.
  5. Hunt for Amatera, ZigCryptoStealer, and NetSupport behaviors: unexpected remote-control binaries, new services, browser-store access from unsigned processes, and crypto-wallet file reads on machines that should never touch a seed phrase.
  6. If you find a single hit, rotate the secrets that box could reach: SSO refresh tokens, VPN profiles, cloud CLI keys, password-manager vaults, and any privileged session that was live. Stealers sell speed. Your rotation has to beat the resale window.

Service Off Is Not the Same as Incident Closed

Security hardening after a disablement is the part teams skip. Policy drift will turn WebClient back on the first time someone “fixes” a mapped-drive ticket. Alert when the service starts on a host that should not have it. Keep that alert in the same queue as your EDR execution rules, because it is the same class of event.

Ongoing threat-protection work is behavioral, not a weekly IOC paste. Watch for remote-admin tools you do not license, browser credential-store access outside the browser’s own process tree, and outbound DAV from subnets that have no file-share exception. Tabletop the share-mount case in your next IR drill: who yanks tokens, who images the box, who checks whether NetSupport called home. If that ownership is fuzzy, the stealer already has a better org chart than you do.

Post-Quantum Origins Will Not Catch a Share Mount

While stealers ride a protocol from the last generation of Windows, the edge is busy upgrading cryptography. Cloudflare’s Automatic Key Exchange probes TLS 1.3-capable origins, learns which key-agreement algorithms they support, and prefers post-quantum connections when the origin can take them. The company frames that as cover for tens of billions of daily origin handshakes. The engineering is real. It is also a tell. Industry attention clusters where the traffic graphs are huge and the story is modern.

Diagram of automatic TLS key-agreement selection between a proxy and origin servers
Origin handshakes can go post-quantum without ever seeing the Windows client that mounted an attacker share.

Your origin can negotiate a beautiful handshake and still lose the laptop that opened dav:// on a phishing tab. That is not an argument against better TLS. It is an argument against letting the fashionable layer monopolize the hardening budget. Defense in depth fails when every extra control sits on the same surface your vendor can screenshot.

Put WebDAV back on the same list as SMBv1 and forgotten RDP. If you cannot explain who needs it, disable it. If you can explain who needs it, log it like privileged file access and page out when the client appears on a machine that should never mount a remote folder. The stealers already made their choice. Your move is to stop pretending the protocol retired because you stopped talking about it.

Frequently Asked Questions

If we block WebDAV at the firewall, are we done?
Blocking helps on subnets that should never speak DAV, and you should do it. Hosts can still reach attacker infrastructure over ordinary HTTPS if the policy is port-only, and a laptop that left the office can mount a share on another network. Pair the edge block with a disabled WebClient service and a hunt for payloads that already ran.
We do not use mapped drives. Can we ignore this chain?
Users do not need a persistent mapped drive for WebDAV to work as an installer. A lure that triggers the client once is enough. Confirm the service is actually off in the image, not merely unused in a diagram, then keep the start-event alert so a “quick fix” ticket cannot silently restore it.
Do endpoint signatures replace turning the client off?
Signatures and behavioral rules are necessary for Amatera, crypto stealers, and NetSupport, because some box will miss the policy. They are a detection layer, not a substitute for removing the mount path. If the share never comes up, the rest of the chain has to work much harder.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.