ClearFake is a long-running web-injection malware-delivery operation, also tracked as UNC5142, that compromises legitimate websites and injects malicious JavaScript, including through malicious Cloudflare Workers. It uses EtherHiding on BNB Smart Chain smart contracts to retrieve staged browser code, configuration, or payload-routing data, complicating infrastructure disruption and allowing operators to change delivery content dynamically. ClearFake commonly presents Google-styled fake CAPTCHA or browser-update overlays that use ClickFix social engineering to persuade visitors to paste and execute attacker-controlled commands.
Windows infection chains have abused native components such as the Run dialog, WebDAV, rundll32, PowerShell, and msbuild to execute staged loaders. Observed ClearFake activity has delivered Amatera (also known as ACR Stealer), ZigCryptoStealer, SectopRAT, Lumma Stealer, Rhadamanthys, and remote-access tooling. Associated payloads have stolen browser credentials, cookies and session material, cryptocurrency-wallet data, payment data, password-manager data, messaging-application data, and sensitive files. Some branches perform cryptocurrency clipboard replacement, terminate endpoint-security processes through bring-your-own-vulnerable-driver techniques, use DLL side-loading or hollowing, deploy reverse proxies, or establish scheduled-task persistence for remote-access software.
ClearFake browser logic performs operating-system detection and has delivered platform-specific payloads to Windows and macOS users. Activity observed at a Ukrainian government organization in 2026 was assessed as part of a broader opportunistic credential- and cryptocurrency-theft operation. A remote-loader branch was tracked as UAT-10820; its operator was assessed with moderate confidence to be Russian-speaking.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ClearFake has expanded a fake CAPTCHA scam into a chain that steals cryptocurrency and credentials while disabling endpoint protection.
The technique stack points at the ClickFix and EtherHiding malware-as-a-service ecosystem that grew out of CLEARFAKE and CLEARSHORT...
“VexTrio Viper runs the largest and oldest known TDS with over 165 affiliates including SocGholish and ClearFake.”
28 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK Mapping ... Resource Development Acquire Infrastructure: Domains T1583.001 joscramp[.]top + 7 co-hosted domains via Dynadot
MITRE ATT&CK Mapping ... Resource Development Acquire Infrastructure: Server T1583.004 Google Cloud VM with custom DNS/mail infrastructure
Trois acteurs identifiés exploitent cette opportunité en rachetant ces domaines expirés (dropcatch) pour hériter du trafic victime et le rediriger vers leurs propres arnaques ou malwares.
CLEARFAKE Mitre ATT&CK TTPs T1059.001 - Command and Scripting Interpreter: PowerShell
The Cloudflare Worker injects JavaScript that queries BNB Smart Chain contracts to retrieve encoded JavaScript.
often using fake CAPTCHA lures to trick users into executing code via malicious copy and paste (aka paste and run, ClickFix, fakeCAPTCHA)
The script overlays a fake Google CAPTCHA-style checkbox onto the compromised page, instructing the victim to open the Windows Run dialog, paste the clipboard contents, and press Enter.
JADESNOW utilizes EtherHiding to fetch, decrypt, and execute malicious payloads from smart contracts on the BNB Smart Chain and Ethereum. The input data stored in the smart contract may be Base64-encoded and XOR-encrypted.
CLEARFAKE Mitre ATT&CK TTPs T1027.010 - Obfuscated Files or Information: Command Obfuscation
JADESNOW utilizes EtherHiding to fetch, decrypt, and execute malicious payloads from smart contracts on the BNB Smart Chain and Ethereum. The input data stored in the smart contract may be Base64-encoded and XOR-encrypted.
"ChromeSetup.exe downloads and executes the Microsoft Software Installer (MSI) package..." and "switches intended to avoid detection: /qn /quiet /norestart"
This stage performs several environment checks, such as inspecting for headless browser frameworks and evaluating the system’s user-agent string. If automated browsing behavior is detected, the execution chain terminates.
Fingerprint the victim using the User-Agent: The operating system; The web browser.
This stage performs several environment checks, such as inspecting for headless browser frameworks and evaluating the system’s user-agent string. If automated browsing behavior is detected, the execution chain terminates.
MITRE ATT&CK™ Matrix - Windows ... Command and Control Standard Application Layer Protocol
Amatera resolves its C2 through an encoded IP address hosted in a Telegraph page; EtherHiding retrieves content from BNB Smart Chain contracts.
The actor uses the contract as remotely changeable storage for encoded JavaScript, a technique known as EtherHiding... Amatera is known to use the Steam community profiles as C2 dead drop resolvers.
ClearFake fetches and executes base64 encoded and gzip compressed code... The initial smart contract delivers an obfuscated JavaScript payload... dynamically retrieves platform specific second-stage payloads... Java Stealer... continuously monitors the clipboard and further downloads additional payloads.
242 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
45 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Framework de compromission web utilisé pour injecter du JavaScript malveillant sur des sites compromis, récupérer des charges depuis des contrats BNB Smart Chain via EtherHiding, et pousser les victimes à exécuter des commandes ClickFix qui déclenchent le chargement de DLL par WebDAV.
A compromised-website malware delivery framework that injects browser code, uses blockchain-hosted instructions and fake CAPTCHA/ClickFix prompts to trick users into executing WebDAV-delivered payloads. Observed branches deploy credential and cryptocurrency stealers or persistent remote-access capability.
A malicious web-injection and delivery framework that compromises websites, presents ClickFix fake CAPTCHA prompts, and coerces victims into executing WebDAV-delivered payloads. It uses blockchain-hosted instructions and supports branches deploying credential/crypto theft and remote-access payloads.
A malicious JavaScript-based delivery framework used here to inject code into compromised websites, retrieve staged code from BNB Smart Chain contracts via EtherHiding, profile victims, and present ClickFix fake-verification prompts that execute the WebDAV-delivered Amatera loader.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.