Cybersecuritynews
ClearFake Malware Campaign Uses Proxy Execution for PowerShell Attacks
First seen 22 Jan 2026, 21:42 UTC
•
•82% similarity
•26.6
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
The ClearFake malware campaign has evolved to exploit a command injection vulnerability in trusted Windows components, enabling the execution of malicious PowerShell commands. This sophisticated operation has compromised hundreds of websites since August 2025, utilizing a fake CAPTCHA to deliver malware while evading detection systems.
ThreatCluster AI
Timeline
2025-08-01
ClearFake campaign began exploiting websites.
Recent
New phase of ClearFake malware deployed.