ClearFake is a financially motivated cybercrime activity cluster first identified in 2023 that compromises legitimate websites and injects malicious HTML and JavaScript to deliver malware through fake browser update and ClickFix-style social-engineering lures. The cluster is widely associated with drive-by delivery from compromised websites, including fake CAPTCHA prompts and clipboard-based copy-and-paste execution chains that trick victims into launching malicious commands through Windows Run, PowerShell, or MSHTA. ClearFake has also been linked to EtherHiding, using blockchain-hosted content to stage malicious scripts and reduce infrastructure visibility. ClearFake operates as a web-inject framework rather than a single malware family. Observed campaigns have delivered multiple payloads over time, including Lumma Stealer, Amatera Stealer, NetSupport RAT, Rhadamanthys, Vidar, and other loaders and stealers. In 2024 and 2025, ClearFake was repeatedly observed using compromised websites to present fake browser or certificate-related prompts, then delivering multi-stage PowerShell, JavaScript, DLL sideloading, and in-memory execution chains. Reported tradecraft includes Keitaro-based traffic filtering, malicious clipboard injection, MSHTA execution, PowerShell obfuscation, anti-analysis checks, DLL sideloading, process injection, and use of legitimate signed binaries or trusted Windows components to proxy execution and evade defenses. ClearFake was an early and prominent adopter of the ClickFix technique and helped popularize user-execution chains based on fake CAPTCHA or fake remediation prompts. Campaigns attributed to the cluster have used malicious JavaScript on compromised WordPress and other websites to selectively serve lures and malware, often with filtering and staging infrastructure designed to frustrate automated analysis. Researchers have also linked ClearFake infrastructure and delivery chains to ACR Stealer and its later Amatera Stealer variant, as well as to Lumma Stealer and NetSupport RAT campaigns. ClearFake is consistently characterized as a cybercriminal cluster engaged in malware delivery and credential theft rather than espionage. Public reporting has not established a high-confidence nation-state attribution. It is also tracked by Google as UNC5142 in connection with EtherHiding-related activity. Known aliases include ClearFake and UNC5142.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
46 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
21 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named cybercriminal actor referenced as an example of actors that compromise websites and insert scripts contacting attacker-controlled domains, creating domains later exploited by dropcatch actors.
Referenced as an example of a threat actor using compromised websites for credential theft and downstream exploitation.
Activity cluster using injected JavaScript on compromised websites to deliver malware via drive-by downloads and fake CAPTCHA/paste-and-run lures.
Web-inject activity cluster delivering ACR Stealer via JavaScript injected into compromised websites.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.