logo

Threat Actors Hijacking Websites To Deliver .NET-Based Malware

ID: 38a33ec3-2fe8-5a31-bfa0-333aebbad5d8

STIX ID: report--38a33ec3-2fe8-5a31-bfa0-333aebbad5d8

Feed Name: cybersecurityNews.com

Threat Score
65/100

Date Published: 2024-08-09

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Clearlake (ClearFake) is an active campaign that compromises legitimate websites to distribute .NET-based fake antivirus and other malware, using public code-hosting services (GitHub, Bitbucket) and URL shorteners to mask payloads; the report includes IoCs (infected site, payload URL, smart contract, repository links) and cautions users about fake update prompts and the misuse of legitimate online resources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.