ClearFake is an unattributed, financially motivated cybercrime activity cluster first identified in 2023. It compromises legitimate websites and injects malicious HTML and JavaScript to deliver malware through fake browser-update, certificate-warning, and CAPTCHA-style lures. ClearFake was an early adopter of ClickFix social engineering, in which a lure copies a malicious command to a visitor’s clipboard and instructs the visitor to execute it through the Windows Run dialog or a shell. ClearFake commonly uses compromised WordPress and other websites as drive-by delivery infrastructure, selectively presenting malicious overlays to intended visitors. Its campaigns have used EtherHiding and blockchain-based dead-drop resolution to obtain staging content or payload locations, as well as traffic-distribution infrastructure for filtering and delivery. Observed execution chains employ PowerShell, MSBuild, trusted Windows utilities, in-memory loaders, anti-analysis checks, AMSI and Event Tracing for Windows bypasses, and DLL side-loading. ClearFake has delivered a range of malware, including Amatera Stealer (formerly ACR Stealer), Lumma Stealer, Rhadamanthys, NetSupport RAT, DarkGate, Matanbuchus, and CastleRAT. Follow-on payloads have included information stealers, remote-access tools, cryptocurrency-mining components, and additional loaders. Amatera-focused ClearFake campaigns have targeted browser data, credentials, authentication tokens, cryptocurrency wallets, password managers, messaging applications, and other locally accessible information. ClearFake is distinct from TA569/SocGholish and has not been publicly attributed to a specific tracked threat actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
45 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
43 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Historically associated with EtherHiding-based fake browser-update and ClickFix delivery chains that lead to infostealer or RAT payloads. It is cited as background for the technique, not as affiliated with HexMage.
Threat cluster delivering infections via ClickFix-style social engineering, including fake CAPTCHA lures on compromised legitimate websites, and used here to distribute WordlistLoader leading to Amatera infections.
Activity cluster using compromised websites, drive-by delivery, and fake CAPTCHA/copy-paste lures to execute malware.
Named cybercriminal actor referenced as an example of actors that compromise websites and insert scripts contacting attacker-controlled domains, creating domains later exploited by dropcatch actors.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.