ClearFake is a malicious JavaScript framework and web-inject activity cluster that compromises legitimate websites, often WordPress sites, and injects malicious HTML/JavaScript to deliver malware to visitors. First recognized in July 2023, it initially used fake browser update lures masquerading as Google Chrome updates, then evolved to fake browser errors, fake Cloudflare Turnstile, fake reCAPTCHA, and broader ClickFix-style social engineering. On compromised sites, ClearFake commonly places a malicious command in the victim’s clipboard and instructs the user to execute it via Win+R or similar workflows, enabling malware delivery without a traditional exploit. It has also been described as delivering malware through drive-by download techniques.
A defining feature of ClearFake is its use of EtherHiding: it retrieves staged JavaScript, routing logic, keys, commands, and related data from smart contracts on the Binance Smart Chain, including BSC testnet, via public RPC endpoints. Multiple reports describe ClearFake fetching and executing Base64-encoded, gzip-compressed, or otherwise obfuscated code from blockchain-hosted content, using anti-analysis checks and, in some variants, separate smart contracts for Windows/macOS payload logic and victim tracking. Later variants also hosted components on Cloudflare Pages and jsDelivr to complicate takedown and blocklisting. Expel reported a public UUID tracker smart contract used to avoid reinfecting victims and estimated one wave likely infected up to 147,521 systems since late August 2025; other reporting cited roughly 149,199 UUID submissions and over 9,300 compromised sites as of February 2025.
Observed infection chains show ClearFake delivering multiple malware families over time. Reported payloads include Amadey, IDAT Loader, Hijack Loader, Emmenhtal Loader v2, Lumma Stealer, Stealc, Vidar, Rhadamanthys, Amatera Stealer, AMOS Stealer for macOS, SectopRAT, and ACRStealer. In one May 2025 chain, a fake CAPTCHA instructed the victim to run a PowerShell command that downloaded a malicious .csproj file and executed it with msbuild.exe, leading to an injector that disabled PowerShell logging, bypassed AMSI and ETW, used Early Bird and Context Hijack injection, and ultimately deployed Amatera Stealer. In later campaigns, ClearFake shifted from mshta.exe abuse to proxy execution via the legitimate Windows script C:\Windows\System32\SyncAppvPublishingServer.vbs to launch hidden PowerShell. Trend Micro also reported a Windows chain that loaded a remote DLL in memory via WebClient and rundll32.exe and dropped pythonw.exe, helper.py, and a malicious libvlccore.dll associated with ACRStealer; macOS users were routed to separate payloads based on browser OS detection.
ClearFake is associated in the content with threat cluster UNC5142 and is repeatedly described as a major ClickFix framework. It has been linked to traffic distribution system activity and affiliate-style malware delivery ecosystems. Targeting is broad and opportunistic: any visitor to a compromised legitimate website may be exposed, with lures localized across many languages and payload selection based on browser and operating system. Known indicators directly mentioned in the content include BSC-related contract addresses such as 0xA1decFB75C8C0CA28C10517ce56B710baf727d2e, 0x46790e2Ac7F3CA5a7D1bfCe312d11E91d23383Ff, 0xf4a32588b50a59a82fbA148d436081A48d80832A, 0x80d31D935f0EC978253A26D48B5593599B9542C7, wallet/deployer addresses including 0xd71f4cdC84420d2bd07F507b7A4F998b4c2d52c9 and 0x9179dda8B285040Bf381AABb8a1f4a1b8c37Ed53, RPC endpoints such as bsc-testnet-rpc.publicnode[.]com, bsc-testnet.drpc[.]org, and data-seed-prebsc-1-s1[.]bnbchain[.]org:8545, and payload/CDN infrastructure including cdn.jsdelivr[.]net/gh/clock-cheking/expert-barnacle/load. Additional reported infrastructure overlaps include Cloudflare-backed disposable delivery domains and shared hosting/IP associations noted in third-party infrastructure analyses.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The CLEARFAKE campaign, associated with the threat cluster UNC5142, functions as a malicious JavaScript framework and often masquerades as a Google Chrome browser update pop-up on compromised websites. The primary function of the embedded JavaScript is to download a payload after a user clicks the "Update Chrome" button.
“VexTrio Viper runs the largest and oldest known TDS with over 165 affiliates including SocGholish and ClearFake.”
18 distinct techniques documented for this family, organized by ATT&CK tactic.
JADESNOW utilizes EtherHiding to fetch, decrypt, and execute malicious payloads from smart contracts on the BNB Smart Chain and Ethereum. The input data stored in the smart contract may be Base64-encoded and XOR-encrypted.
JADESNOW utilizes EtherHiding to fetch, decrypt, and execute malicious payloads from smart contracts on the BNB Smart Chain and Ethereum. The input data stored in the smart contract may be Base64-encoded and XOR-encrypted.
"ChromeSetup.exe downloads and executes the Microsoft Software Installer (MSI) package..." and "switches intended to avoid detection: /qn /quiet /norestart"
This stage performs several environment checks, such as inspecting for headless browser frameworks and evaluating the system’s user-agent string. If automated browsing behavior is detected, the execution chain terminates.
Fingerprint the victim using the User-Agent: The operating system; The web browser.
This stage performs several environment checks, such as inspecting for headless browser frameworks and evaluating the system’s user-agent string. If automated browsing behavior is detected, the execution chain terminates.
MITRE ATT&CK™ Matrix - Windows ... Command and Control Standard Application Layer Protocol
Threat actors store data (for example C2 configuration) or code on a public blockchain... they can access it through a legitimate API endpoint... SharkStealer and ArechClient2... pull their C2 configuration from a smart contract... ZigCryptoStealer... uses smart contracts to receive their C2 configuration.
ClearFake fetches and executes base64 encoded and gzip compressed code... The initial smart contract delivers an obfuscated JavaScript payload... dynamically retrieves platform specific second-stage payloads... Java Stealer... continuously monitors the clipboard and further downloads additional payloads.
222 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
33 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named campaign/family associated with large-scale ClickFix-style infection waves.
A related malicious framework referenced for comparison because it also uses ClickFix-style lures and EtherHiding for malware delivery.
A web-based malware delivery framework that compromises legitimate websites and uses BNB Smart Chain testnet smart contracts to host and retrieve malicious JavaScript, enabling resilient payload delivery and anti-takedown command routing. It uses fake CAPTCHA/ClickFix lures and OS-aware staging to deliver follow-on malware to Windows and macOS victims.
A malware family using EtherHiding to fetch additional JavaScript payloads; it retrieves and executes base64-encoded, gzip-compressed code from smart contracts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.