ClearFake is a financially motivated malware-distribution activity cluster active since at least mid-2023. It compromises legitimate websites, frequently WordPress sites, and injects JavaScript to expose visitors to fake browser-update prompts and fake CAPTCHA verification lures. Its ClickFix campaigns persuade users to paste and execute attacker-supplied commands, enabling malware installation through social engineering rather than requiring exploitation of an endpoint software vulnerability. The distribution infrastructure supports operating-system-specific delivery stages for Windows and macOS. ClearFake pioneered EtherHiding-based malicious-code staging on BNB Smart Chain after disruption of its conventional delivery infrastructure. Operators store encoded JavaScript and delivery instructions in smart contracts, creating staging infrastructure resistant to conventional hosting takedowns. Campaigns also abuse Cloudflare Workers to inject browser code into compromised websites. Windows infection chains have used WebDAV-delivered DLLs and ordinal-based execution through rundll32 to launch information stealers and subsequent payloads. Malware distributed through ClearFake includes ACR Stealer, Amatera, WordlistLoader, ZigCryptoStealer, and CastleRAT. Observed chains steal credentials, browser data, cryptocurrency-wallet information, and sensitive files. ZigCryptoStealer replaces cryptocurrency addresses copied to the clipboard with attacker-controlled addresses. Associated delivery chains employ DLL side-loading, process injection, and signed vulnerable drivers to terminate endpoint-security processes. Follow-on tooling includes reverse proxies and unauthorized NetSupport Manager installations with hidden interfaces and scheduled-task persistence. WordlistLoader adds word-based payload encoding, security-hook removal, Event Tracing for Windows bypasses, and anti-analysis measures. ClearFake-associated delivery activity has affected a Ukrainian government organization, although the intrusion formed part of a broader credential and cryptocurrency theft operation rather than an exclusively government-focused campaign. ClearFake denotes a campaign and activity cluster; its use by malware distributors does not establish that every downstream payload or affiliate campaign is controlled by a single operator.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
47 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
73 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named activity cluster cited as an example of malware-related domain abuse. The content associates ClearFake with JavaScript lures injected into compromised websites, predominantly WordPress sites, concentrated abuse of .garden domains, and a spike in botnet command servers under .ru.
Used the EtherHiding blockchain dead-drop technique to place malicious code in BNB Smart Chain smart contracts after distribution servers were disrupted, enabling resilient malware delivery and command-and-control configuration retrieval.
Cybercriminal operators associated with the emergence of EtherHiding, a blockchain dead-drop approach that uses smart contracts on Binance Smart Chain for resilient storage or retrieval of malicious infrastructure data.
A cybercriminal operation that adopted EtherHiding in 2023, storing malicious code in Binance Smart Chain smart contracts to maintain resilient malware-delivery infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.