
Findings and evidence
Cisco Talos investigates unusual WebDAV-related endpoint activity and reconstructs two related delivery chains involving Amatera. The secondary payloads differed, illustrating why similar early events do not always lead to an identical incident outcome.
Why it matters
Separate directly observed events from reconstructed earlier stages. Preserve timing, collection source and confidence for each link when combining endpoint telemetry with external malware intelligence.
Scope and limits
Talos uses moderate-confidence assessments for parts of the campaign. Similar delivery behavior is not sufficient to attribute every case to the same operator.
Primary source
Cisco Talos: original publication. Source published 2026-09-08. Brief prepared by websec.gr on 26 September 2026. This is an editorial research summary, not a claim of independent replication.