ClearFake Campaign is a threat campaign tracked across 1 threat cluster and 2 intelligence report mentions on ThreatCluster. First observed January 22, 2026; most recent activity January 22, 2026.
ClearFake is a malware campaign that leverages proxy execution to run PowerShell commands by abusing a trusted Windows feature. By using legitimate Windows components to execute malicious payloads, it aims to bypass defenses and enable stealthy command execution and deployment of malware. The campaign is significant because it demonstrates attackers abusing trusted OS features to perform command execution, increasing resilience against endpoint controls.
The ClearFake malware campaign has evolved to exploit a command injection vulnerability in trusted Windows components, enabling the execution of malicious PowerShell commands. This sophisticated operation has…