ClearFake is a malicious JavaScript-based malware-delivery framework and activity cluster, associated with UNC5142, active since at least 2023. Operators compromise legitimate websites, frequently WordPress sites, and inject scripts that expose visitors to drive-by malware delivery. Early campaigns impersonated browser updates; later variants adopted fake browser errors, reCAPTCHA or Cloudflare-style verification overlays, and ClickFix social engineering. These lures place attacker-controlled commands on the victim clipboard and instruct victims to manually execute them, commonly through the Windows Run dialog or terminal interfaces.
ClearFake uses EtherHiding to retrieve staging code, payload-routing data, commands, and lure components from blockchain smart contracts, including BNB Smart Chain testnet infrastructure. This decentralized dead-drop-resolution design enables operators to rotate infrastructure and alter delivery logic without changing the initial injected website code. The framework performs browser-based operating-system detection and can route Windows and macOS victims to distinct infection chains.
ClearFake has delivered a broad range of follow-on malware, including Amatera (ACR) Stealer, Lumma Stealer, Vidar, Stealc, Rhadamanthys, SectopRAT, and loaders such as Emmenhtal Loader and HijackLoader. Resulting infections can enable theft of browser credentials, cookies, payment data, cryptocurrency-wallet data, and other sensitive information, as well as remote access. ClearFake is a delivery framework rather than a single payload family; its operators or affiliates can change the malware delivered to victims over time.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The technique stack points at the ClickFix and EtherHiding malware-as-a-service ecosystem that grew out of CLEARFAKE and CLEARSHORT...
“VexTrio Viper runs the largest and oldest known TDS with over 165 affiliates including SocGholish and ClearFake.”
24 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK Mapping ... Resource Development Acquire Infrastructure: Domains T1583.001 joscramp[.]top + 7 co-hosted domains via Dynadot
MITRE ATT&CK Mapping ... Resource Development Acquire Infrastructure: Server T1583.004 Google Cloud VM with custom DNS/mail infrastructure
CLEARFAKE Mitre ATT&CK TTPs T1059.001 - Command and Scripting Interpreter: PowerShell
CLEARFAKE Mitre ATT&CK TTPs T1059.007 - Command and Scripting Interpreter: Javascript
JADESNOW utilizes EtherHiding to fetch, decrypt, and execute malicious payloads from smart contracts on the BNB Smart Chain and Ethereum. The input data stored in the smart contract may be Base64-encoded and XOR-encrypted.
CLEARFAKE Mitre ATT&CK TTPs T1027.010 - Obfuscated Files or Information: Command Obfuscation
JADESNOW utilizes EtherHiding to fetch, decrypt, and execute malicious payloads from smart contracts on the BNB Smart Chain and Ethereum. The input data stored in the smart contract may be Base64-encoded and XOR-encrypted.
"ChromeSetup.exe downloads and executes the Microsoft Software Installer (MSI) package..." and "switches intended to avoid detection: /qn /quiet /norestart"
This stage performs several environment checks, such as inspecting for headless browser frameworks and evaluating the system’s user-agent string. If automated browsing behavior is detected, the execution chain terminates.
Fingerprint the victim using the User-Agent: The operating system; The web browser.
This stage performs several environment checks, such as inspecting for headless browser frameworks and evaluating the system’s user-agent string. If automated browsing behavior is detected, the execution chain terminates.
MITRE ATT&CK™ Matrix - Windows ... Command and Control Standard Application Layer Protocol
Threat actors store data (for example C2 configuration) or code on a public blockchain... they can access it through a legitimate API endpoint... SharkStealer and ArechClient2... pull their C2 configuration from a smart contract... ZigCryptoStealer... uses smart contracts to receive their C2 configuration.
ClearFake fetches and executes base64 encoded and gzip compressed code... The initial smart contract delivers an obfuscated JavaScript payload... dynamically retrieves platform specific second-stage payloads... Java Stealer... continuously monitors the clipboard and further downloads additional payloads.
231 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
40 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A historically referenced EtherHiding-associated fake browser-update delivery cluster. It is discussed as background for the payload-staging technique and is not linked to HexMage.
An activity cluster that compromises websites and injects JavaScript to deliver malware through drive-by downloads and fake CAPTCHA/copy-paste lures.
A long-running malicious operation that compromises legitimate websites and uses fake CAPTCHA overlays and ClickFix-style social engineering to trick users into executing malicious commands that deliver malware.
Named malware/campaign associated here with website compromise and malicious script injection contacting attacker-controlled domains.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.