logo

New Execution Technique in ClearFake Campaign

ID: 870e7de3-d716-521e-a5bb-261441a3a71c

STIX ID: report--870e7de3-d716-521e-a5bb-261441a3a71c

Feed Name: ReliaQuest Blog

Threat Score
70/100

Date Published: 2024-05-31

Date Updated: 2026-04-29

...
...

ReliaQuest observed a ClearFake JavaScript framework campaign that tricks victims into manually pasting obfuscated PowerShell into a shell to fetch and execute additional stages, performing sandbox-evasion (CPU temperature check), DLL sideloading of a malicious MediaInfo DLL, and ultimately installing LummaC2 infostealer; the report includes case studies, IoCs (hashes, domains, IPs), and mitigation recommendations such as restricting PowerShell, applying WDAC/AMSI, network filtering, and user awareness.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.