ClearFake's New Variant: Web3 Exploitation for Malware Delivery
ID: a5c24cc2-8981-5da2-a2c3-5542797b831a
STIX ID: report--a5c24cc2-8981-5da2-a2c3-5542797b831a
Feed Name: Sekoia.com
This report presents a technical analysis of ClearFake, a persistent and evolving malicious JavaScript framework that compromises websites (notably WordPress) to serve realistic ClickFix lures (fake reCAPTCHA/Cloudflare Turnstile) and trick victims into executing PowerShell commands; the operator now stores obfuscated JavaScript, AES keys, lure URLs and PowerShell commands on the Binance Smart Chain (EtherHiding) to fetch and decrypt stages, resulting in Emmenhtal loader and subsequent Lumma and Vidar stealer infections; the document includes detailed technical workflows, IoCs (wallets, lure and payload URLs, PowerShell commands), and parsing/decryption scripts to support detection and remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
