ClearFake is a malware-distribution operation and activity cluster that uses malicious JavaScript injected into compromised legitimate websites, frequently WordPress sites, to deliver additional malware. Its lures have evolved from fake browser updates to fake CAPTCHA verification prompts using ClickFix social engineering. These prompts persuade visitors to copy and execute attacker-controlled commands, turning ordinary website visits into user-assisted initial access. ClearFake includes operating-system-specific stages for Windows and macOS.
ClearFake operators adopted EtherHiding on BNB Smart Chain in 2023, storing malicious code or delivery information in smart contracts. Injected browser scripts retrieve encoded JavaScript from these contracts, allowing operators to update delivery stages and reduce dependence on conventional hosting infrastructure. Malicious Cloudflare Workers have also been used in its website-based delivery chains.
Observed Windows campaigns use fake Google CAPTCHA prompts to instruct victims to execute clipboard commands through the Run dialog. Some commands access remote WebDAV resources and invoke malicious DLLs through ordinal-based execution. Delivered malware includes Amatera information stealer, WordlistLoader, ZigCryptoStealer, CastleRAT, and unauthorized NetSupport Manager deployments. Follow-on tooling can steal credentials and cryptocurrency-related data, replace cryptocurrency addresses on the clipboard, provide remote access, and relay network connections. Particular infection chains employ DLL sideloading, in-memory loading, and vulnerable signed drivers to terminate endpoint security processes; remote-access deployments can establish scheduled-task persistence.
ClearFake supports broad, financially motivated malware distribution rather than a single industry-specific intrusion campaign. Associated activity has affected a Ukrainian government organization, but that observation does not establish exclusive government targeting. Cisco Talos tracks an associated remote-loader branch as UAT-10820.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ClearFake has expanded a fake CAPTCHA scam into a chain that steals cryptocurrency and credentials while disabling endpoint protection.
The technique stack points at the ClickFix and EtherHiding malware-as-a-service ecosystem that grew out of CLEARFAKE and CLEARSHORT...
“VexTrio Viper runs the largest and oldest known TDS with over 165 affiliates including SocGholish and ClearFake.”
29 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK Mapping ... Resource Development Acquire Infrastructure: Domains T1583.001 joscramp[.]top + 7 co-hosted domains via Dynadot
MITRE ATT&CK Mapping ... Resource Development Acquire Infrastructure: Server T1583.004 Google Cloud VM with custom DNS/mail infrastructure
Trois acteurs identifiés exploitent cette opportunité en rachetant ces domaines expirés (dropcatch) pour hériter du trafic victime et le rediriger vers leurs propres arnaques ou malwares.
CLEARFAKE Mitre ATT&CK TTPs T1059.001 - Command and Scripting Interpreter: PowerShell
The Cloudflare Worker injects JavaScript that queries BNB Smart Chain contracts to retrieve encoded JavaScript.
often using fake CAPTCHA lures to trick users into executing code via malicious copy and paste (aka paste and run, ClickFix, fakeCAPTCHA)
The script overlays a fake Google CAPTCHA-style checkbox onto the compromised page, instructing the victim to open the Windows Run dialog, paste the clipboard contents, and press Enter.
JADESNOW utilizes EtherHiding to fetch, decrypt, and execute malicious payloads from smart contracts on the BNB Smart Chain and Ethereum. The input data stored in the smart contract may be Base64-encoded and XOR-encrypted.
CLEARFAKE Mitre ATT&CK TTPs T1027.010 - Obfuscated Files or Information: Command Obfuscation
JADESNOW utilizes EtherHiding to fetch, decrypt, and execute malicious payloads from smart contracts on the BNB Smart Chain and Ethereum. The input data stored in the smart contract may be Base64-encoded and XOR-encrypted.
"ChromeSetup.exe downloads and executes the Microsoft Software Installer (MSI) package..." and "switches intended to avoid detection: /qn /quiet /norestart"
This stage performs several environment checks, such as inspecting for headless browser frameworks and evaluating the system’s user-agent string. If automated browsing behavior is detected, the execution chain terminates.
Fingerprint the victim using the User-Agent: The operating system; The web browser.
This stage performs several environment checks, such as inspecting for headless browser frameworks and evaluating the system’s user-agent string. If automated browsing behavior is detected, the execution chain terminates.
MITRE ATT&CK™ Matrix - Windows ... Command and Control Standard Application Layer Protocol
Amatera resolves its C2 through an encoded IP address hosted in a Telegraph page; EtherHiding retrieves content from BNB Smart Chain contracts.
“The technique, named Blockchain Dead Drops (BDD), stores payloads in on-chain transactions and smart contracts where infected devices can retrieve them on demand.” The article explicitly maps it to “T1102.001 (Web Service: Dead Drop Resolver).”
« Blockchain Dead Drops (BDD) ... stocker des instructions de malware ou des configurations C2 sur des blockchains publiques » ; « Smart contracts sur Polygon utilisés comme résolveurs C2 ».
319 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
52 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Uses malicious JavaScript injected into compromised websites. The article attributes 87 of 89 malware domains in .garden to a single ClearFake cluster and links a spike in .ru botnet command servers to ClearFake.
A malicious fake-CAPTCHA/ClickFix distribution framework used to coerce victims into executing commands that retrieve further payloads.
Malware campaign that adopted smart-contract-based storage on BNB Smart Chain to preserve malicious-code delivery after distribution servers were blocked.
Loader associated in the reference with operators that adopted the EtherHiding blockchain-based dead-drop approach on Binance Smart Chain.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.