ClearFake is a cybercriminal web-inject activity cluster first identified in 2023 that compromises legitimate websites and injects malicious HTML and JavaScript to deliver malware through fake browser update, fake CAPTCHA, and related social-engineering lures. It is widely associated with drive-by delivery chains in which visitors to compromised sites are profiled and then presented with deceptive prompts that persuade them to execute attacker-supplied commands themselves, most notably through the ClickFix or paste-and-run technique. ClearFake has also been linked to EtherHiding, using blockchain-hosted content to conceal or stage malicious scripts. ClearFake primarily operates by abusing compromised web infrastructure rather than exploiting endpoint vulnerabilities. Its infection chains commonly rely on JavaScript-based web injects, clipboard manipulation, fake certificate or browser-fix prompts, and command execution via Windows utilities such as PowerShell, mshta, and msbuild. Reported tradecraft includes multi-stage in-memory loaders, sandbox-evasion checks, AMSI and ETW bypass attempts, use of traffic distribution systems for filtering and redirection, and delivery of additional payloads through staged scripts and archives. ClearFake has been described as an early adopter and prominent user of ClickFix-style user-execution tradecraft. Payloads delivered through ClearFake infrastructure have included Lumma Stealer, Amatera Stealer, ACR Stealer, NetSupport RAT, Rhadamanthys, Vidar, and other commodity malware. Reporting has also linked ClearFake delivery chains to loaders such as DOILoader/HijackLoader and to follow-on malware including Amadey and cryptocurrency-mining components in some campaigns. By 2025 and 2026, ClearFake was assessed as one of the more prevalent fake-update and web-inject clusters in enterprise telemetry. ClearFake is tracked by some researchers as UNC5142 in connection with EtherHiding-related activity. It is generally treated as a financially motivated threat cluster rather than a nation-state actor. No single definitive operator attribution is broadly established, and it is typically discussed as an activity cluster rather than a formally identified group with confirmed membership or command structure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
46 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
21 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Web-inject activity cluster delivering ACR Stealer via JavaScript injected into compromised websites.
Threat cluster identified as using web inject campaigns beyond the TA569 ecosystem.
Threat cluster involved in web-inject campaigns using compromised websites and fake update style delivery.
Activity cluster that injects JavaScript into compromised websites to deliver malware, including via drive-by download techniques; also observed leveraging 'paste and run' as an initial execution technique.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.