ClearFake is a malicious JavaScript framework and malware delivery operation that compromises legitimate websites and injects hidden HTML and JavaScript to present fake browser updates, browser errors, Cloudflare Turnstile prompts, or reCAPTCHA-style verification lures. It emerged in 2023 as a fake-update campaign and later evolved into a prominent ClickFix-style ecosystem in which victims are tricked into manually executing attacker-supplied commands, typically on Windows and in some cases macOS. ClearFake has been associated with the threat cluster UNC5142.
A defining characteristic of ClearFake is its use of EtherHiding, in which attacker-controlled logic, configuration, or staged payload components are retrieved from blockchain smart contracts rather than from static conventional infrastructure alone. Multiple analyses describe ClearFake using Binance Smart Chain, including testnet infrastructure, to store or resolve JavaScript, lure content, encryption material, routing data, and victim-tracking logic. This design complicates takedown and blocking efforts and allows operators to rotate downstream delivery infrastructure while leaving compromised websites in place.
Operationally, ClearFake acts as a web-inject delivery framework rather than a single payload family. Compromised sites load normally at first or are overlaid with social-engineering content that impersonates trusted browser or verification workflows. Earlier variants commonly displayed fake Google Chrome update prompts. Later variants shifted to fake technical issues, fake CAPTCHA checks, and Cloudflare-themed verification pages that copy malicious commands to the clipboard and instruct users to paste and run them. ClearFake has also been described as using drive-by delivery from compromised websites, although many later infections rely on explicit user interaction through ClickFix-style prompts.
ClearFake has delivered a wide range of malware families over time. Reported downstream payloads include Lumma Stealer, Vidar, Stealc, Amadey, IDAT Loader, HijackLoader, Emmenhtal Loader v2, SectopRAT, ACRStealer, and Amatera Stealer, among others. Windows and macOS victims may be routed to different payload chains based on browser-side operating-system detection. Some observed chains used PowerShell, mshta, msbuild, in-memory DLL loading, Python-based loaders or RATs, shellcode injection, and DLL sideloading or proxy-loading techniques. In campaigns delivering stealers, the end goal has included theft of credentials, browser cookies, payment-card data, cryptocurrency-wallet data, and browser sessions.
ClearFake is financially motivated and overlaps with the broader ClickFix and EtherHiding malware-as-a-service ecosystem. It has been compared with or linked operationally to adjacent frameworks such as ErrTraffic and to traffic-distribution and affiliate-style delivery chains. The framework has been observed at significant scale across thousands of compromised websites and large victim volumes, making it one of the more prominent fake-update and fake-verification malware delivery operations targeting web users.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The technique stack points at the ClickFix and EtherHiding malware-as-a-service ecosystem that grew out of CLEARFAKE and CLEARSHORT...
“VexTrio Viper runs the largest and oldest known TDS with over 165 affiliates including SocGholish and ClearFake.”
23 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK Mapping ... Resource Development Acquire Infrastructure: Domains T1583.001 joscramp[.]top + 7 co-hosted domains via Dynadot
MITRE ATT&CK Mapping ... Resource Development Acquire Infrastructure: Server T1583.004 Google Cloud VM with custom DNS/mail infrastructure
JADESNOW utilizes EtherHiding to fetch, decrypt, and execute malicious payloads from smart contracts on the BNB Smart Chain and Ethereum. The input data stored in the smart contract may be Base64-encoded and XOR-encrypted.
CLEARFAKE Mitre ATT&CK TTPs T1027.010 - Obfuscated Files or Information: Command Obfuscation
JADESNOW utilizes EtherHiding to fetch, decrypt, and execute malicious payloads from smart contracts on the BNB Smart Chain and Ethereum. The input data stored in the smart contract may be Base64-encoded and XOR-encrypted.
"ChromeSetup.exe downloads and executes the Microsoft Software Installer (MSI) package..." and "switches intended to avoid detection: /qn /quiet /norestart"
This stage performs several environment checks, such as inspecting for headless browser frameworks and evaluating the system’s user-agent string. If automated browsing behavior is detected, the execution chain terminates.
Fingerprint the victim using the User-Agent: The operating system; The web browser.
This stage performs several environment checks, such as inspecting for headless browser frameworks and evaluating the system’s user-agent string. If automated browsing behavior is detected, the execution chain terminates.
MITRE ATT&CK™ Matrix - Windows ... Command and Control Standard Application Layer Protocol
Threat actors store data (for example C2 configuration) or code on a public blockchain... they can access it through a legitimate API endpoint... SharkStealer and ArechClient2... pull their C2 configuration from a smart contract... ZigCryptoStealer... uses smart contracts to receive their C2 configuration.
ClearFake fetches and executes base64 encoded and gzip compressed code... The initial smart contract delivers an obfuscated JavaScript payload... dynamically retrieves platform specific second-stage payloads... Java Stealer... continuously monitors the clipboard and further downloads additional payloads.
230 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
37 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware/campaign associated here with website compromise and malicious script injection contacting attacker-controlled domains.
Malware/fake-update ecosystem referenced as using compromised websites to steal user credentials and enable further exploitation.
Referenced as part of the broader malware-as-a-service ecosystem from which the observed ClickFix and EtherHiding tradecraft evolved.
A named campaign/family associated with large-scale ClickFix-style infection waves.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.