In recent months, a particularly dangerous malware campaign has emerged that involves you in the attack itself: EVALUSION, an operation that blends social engineering with info-stealing and remote access tools. At TecnetOne, we’ll explain how it works, why it’s spreading so fast, and what you can do to protect yourself.
This campaign was analyzed by researchers at eSentire, who confirmed it's an evolution of the known ClickFix technique—an attack vector where cybercriminals convince users to paste malicious commands into the Windows Run window under the guise of solving a CAPTCHA or completing a “security check.”
Yes, the user unknowingly becomes the installer of the malware.
And as you can guess, that leaves your system wide open.
To understand EVALUSION, you first need to know about ClickFix—a method that’s gaining traction because it bypasses many security systems.
Attackers show a fake verification page, saying things like:
“To verify you’re human, copy and paste this into Windows + R.”
When you do that, you execute a malicious command that launches Windows processes like mshta.exe or PowerShell without your knowledge.
Since you are technically authorizing the action, antivirus and corporate protection tools often don’t flag it.
This is the foundation of EVALUSION.
Read more: EvilAI: The Malware Disguised as an AI Tool
The campaign drops two primary tools:
A next-gen info-stealer (successor to AcridRain), first seen in June 2025. It’s sold as a malware-as-a-service platform, with pricing from $199/month to $1,499/year.
Its most dangerous capabilities include:
It also uses advanced evasion techniques:
In short: it hides where you’d never look.
If Amatera steals your data, NetSupport RAT goes further—it gives attackers remote control of your machine.
Originally a legitimate remote support tool, NetSupport becomes a Remote Access Trojan (RAT) in criminal hands.
One of eSentire’s key findings: Amatera only installs NetSupport RAT if your device is considered valuable.
For example, if you:
The malware skips RAT deployment.
This approach helps attackers:
It’s a surgical campaign designed to maximize profit and minimize risk.
The attack chain is clever and efficient:
The result?
All because you pasted a line thinking it was just a CAPTCHA check.
Amatera and NetSupport RAT (Source: BlackHat)
EVALUSION isn’t alone. Similar campaigns are abusing ClickFix with different malware:
ClickFix has become the new standard in digital deception.
You might also be interested in: The Evolution of Artificial Intelligence Driven Malware
At TecnetOne, we always stress: social engineering is dangerous because it exploits you, not a tech flaw. Protection starts with habits, not just tools.
At TecnetOne, we recommend deploying:
EVALUSION is a perfect case study in modern malware:
The best defense isn’t just software—it’s your ability to spot a trick in time.
If you’d like TecnetOne to review your current security posture, help harden your defenses, or run an employee awareness workshop, we’re here to help.