logo

New ClearFake Campaign Leveraging Proxy Execution to Run PowerShell Commands via Trusted Window Feature

ID: 292e095f-c90f-5c42-9d1f-5e536a1a4da3

STIX ID: report--292e095f-c90f-5c42-9d1f-5e536a1a4da3

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-01-22

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

ClearFake is an active, large-scale malware campaign that disguises malicious loaders as fake CAPTCHA prompts on hundreds of compromised websites; victims are socially engineered to execute a legitimate Windows VBScript (SyncAppvPublishingServer.vbs) from the Run dialog, after which staged payloads delivered via a blockchain-hosted JavaScript and a public CDN can perform data theft, remote access, or further malware execution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.