logo

The CAPTCHA Trap: ClearFake Malware Tricks Users Into Hacking Themselves

ID: 54e27c20-0ee7-52a1-be0d-c1017ee75277

STIX ID: report--54e27c20-0ee7-52a1-be0d-c1017ee75277

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-01-27

Date Updated: 2026-04-23

Author: Ddos

...
...

A sophisticated campaign named ClearFake lures users with fake CAPTCHA prompts that instruct victims to paste a malicious PowerShell command from their clipboard; attackers then abuse a vulnerable Windows script (SyncAppvPublishingServer.vbs) to execute PowerShell stealthily. The campaign stores Base64-encoded JavaScript payloads in immutable Binance Smart Chain smart contracts ("EtherHiding") and leverages jsDelivr CDN to frustrate blocking, enabling takedown-resistant distribution; researchers estimate ~150,000 infections since August 2025.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.