logo

ClearFake's New Variant: Web3 Exploitation for Malware Delivery

ID: a5c24cc2-8981-5da2-a2c3-5542797b831a

STIX ID: report--a5c24cc2-8981-5da2-a2c3-5542797b831a

Feed Name: Sekoia.com

Threat Score
78/100

Date Published: 2025-03-18

Date Updated: 2026-07-20

...
...

This report presents a technical analysis of ClearFake, a persistent and evolving malicious JavaScript framework that compromises websites (notably WordPress) to serve realistic ClickFix lures (fake reCAPTCHA/Cloudflare Turnstile) and trick victims into executing PowerShell commands; the operator now stores obfuscated JavaScript, AES keys, lure URLs and PowerShell commands on the Binance Smart Chain (EtherHiding) to fetch and decrypt stages, resulting in Emmenhtal loader and subsequent Lumma and Vidar stealer infections; the document includes detailed technical workflows, IoCs (wallets, lure and payload URLs, PowerShell commands), and parsing/decryption scripts to support detection and remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.