Cybersecuritynews ClearFake Malware Campaign Uses Proxy Execution for PowerShell Attacks
Article Content
Browse articles
The ClearFake malware campaign has evolved to exploit a command injection vulnerability in trusted Windows components, enabling the execution of malicious PowerShell commands. This sophisticated operation has compromised hundreds of websites since August 2025, utilizing a fake CAPTCHA to deliver malware while evading detection systems.
Ask AI about this cluster
Answers cite the sources they use
Updated 193d ago How this analysis works
Timeline
2025-08-01
ClearFake campaign began exploiting websites.
Recent
New phase of ClearFake malware deployed.
More articles in this cluster (2)
Following this threat?
Track ClearFake in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Surge in Blockchain Dead Drops Driven by AI Models Cyber threat actors have significantly increased the use of blockchain dead drops (BDDs) to hide malware instructions, with a 440% surge in activity since mid-2025, attributed to unrestricted Chinese open-source AI models. This technique allows attackers, particularly state-linked groups from North Korea and Iran, to…
Node.js Exploited in Ransomware Attacks Using EtherHiding Technique Since February 2026, threat actors have been exploiting the trusted Node.js runtime to deploy malicious payloads in targeted attacks against government departments, technology companies, and hotels. The technique leverages node.exe, a legitimate and signed developer tool, allowing attackers to run interpreted scripts…