ClearFake Campaign — Campaign Analysis & Threat Activity

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
January 22, 2026
Last Seen
January 22, 2026

ClearFake Campaign is a threat campaign tracked across 1 threat cluster and 2 intelligence report mentions on ThreatCluster. First observed January 22, 2026; most recent activity January 22, 2026.

Overview

ClearFake is a malware campaign that leverages proxy execution to run PowerShell commands by abusing a trusted Windows feature. By using legitimate Windows components to execute malicious payloads, it aims to bypass defenses and enable stealthy command execution and deployment of malware. The campaign is significant because it demonstrates attackers abusing trusted OS features to perform command execution, increasing resilience against endpoint controls.

Related Threat Clusters

Recent Intelligence Reports

  • New ClearFake Campaign Leveraging Proxy Execution to Run PowerShell Commands via Trusted Window Feature — Cybersecuritynews · January 22, 2026
  • ClearFake malware Exploits Proxy Execution to Run Malicious PowerShell Commands via Trusted Windows Feature — Gbhackers · January 22, 2026

CVSS v3.1 Breakdown