ClearFake’s New Widespread Variant: Increased Web3 Exploitation for Malware Delivery
ID: 39a891d2-6937-5531-83ed-fe91fb6311f2
STIX ID: report--39a891d2-6937-5531-83ed-fe91fb6311f2
Feed Name: Sekoia.io Blog
Date Published: 2025-03-18
Date Updated: 2026-04-29
Author: Pierre Le Bourhis, Quentin Bourgue and Sekoia TDR
ClearFake is a malicious JavaScript framework that compromises websites (primarily WordPress) to perform drive-by downloads using Web3-based "EtherHiding" on the Binance Smart Chain. The framework fetches compressed/encoded JavaScript and AES-encrypted lure pages from smart contracts, presents social-engineering lures (fake reCAPTCHA / Cloudflare Turnstile) to trick users into executing PowerShell commands, and ultimately delivers loaders (Emmenhtal) and infostealers (Lumma, Vidar). The report provides detailed technical analysis, IoCs (wallet addresses, smart contract ABIs, lure and payload URLs, PowerShell commands), and scripts to parse and decrypt the malicious artifacts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
