logo

ClearFake gets more evasive with new living off the land (LOTL) techniques

ID: 627e4a20-0f19-5556-8004-510ab57cd21e

STIX ID: report--627e4a20-0f19-5556-8004-510ab57cd21e

Feed Name: Expel Blog

Threat Score
78/100

Date Published: 2026-01-20

Date Updated: 2026-04-27

Author: Marcus Hutchins

...
...

ClearFake is a widespread, highly evasive JavaScript-based malware campaign that compromises websites to display fake CAPTCHA social-engineering lures; the injected code dynamically retrieves staged payloads from BNB smart contracts (EtherHiding), then uses clipboard-pasted commands to execute in-memory PowerShell fetched via a CDN. The actors employ proxy execution by abusing SyncAppvPublishingServer.vbs to evade EDRs, track infections via blockchain-stored UUIDs (≈149,199 submissions), and frequently rotate hosting, making detection and takedown difficult; the report includes smart contract addresses, wallet, and payload URL IOCs and defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.