logo

ClearFake’s New Widespread Variant: Increased Web3 Exploitation for Malware Delivery

ID: 39a891d2-6937-5531-83ed-fe91fb6311f2

STIX ID: report--39a891d2-6937-5531-83ed-fe91fb6311f2

Feed Name: Sekoia.io Blog

Threat Score
78/100

Date Published: 2025-03-18

Date Updated: 2026-04-29

Author: Pierre Le Bourhis, Quentin Bourgue and Sekoia TDR

...
...

ClearFake is a malicious JavaScript framework that compromises websites (primarily WordPress) to perform drive-by downloads using Web3-based "EtherHiding" on the Binance Smart Chain. The framework fetches compressed/encoded JavaScript and AES-encrypted lure pages from smart contracts, presents social-engineering lures (fake reCAPTCHA / Cloudflare Turnstile) to trick users into executing PowerShell commands, and ultimately delivers loaders (Emmenhtal) and infostealers (Lumma, Vidar). The report provides detailed technical analysis, IoCs (wallet addresses, smart contract ABIs, lure and payload URLs, PowerShell commands), and scripts to parse and decrypt the malicious artifacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.