ClearFake is a malware family observed leveraging a proxy execution technique to run malicious PowerShell commands by abusing a Trusted Windows Feature.
Overview
ClearFake is a malware family observed leveraging a proxy execution technique to run malicious PowerShell commands by abusing a Trusted Windows Feature. This living-off-the-land approach uses legitimate Windows components to execute payloads, enabling stealthy operations and potential evasion of security controls.
Related Threat Clusters
-
North Korean Hackers Utilize EtherHiding for Cryptocurrency Theft
The Google Threat Intelligence Group (GTIG) reports that North Korean threat actor UNC5342 has adopted a new technique called EtherHiding to deliver malware and facilitate cryptocurrency theft. This method embeds…
3 articles · Updated May 26, 2026 -
Cybercriminals Exploit BNB Chain for Malware via Fake CAPTCHAs
Microsoft Threat Intelligence has reported a new malware campaign utilizing the BNB Smart Chain, employing a technique called EtherHiding. This method allows hackers to store malicious code within blockchain smart…
12 articles · Updated August 7, 2026 -
SmartApeSG Targets Okendo Reviews Widget in Supply Chain Attack
On May 14, 2026, the SmartApeSG threat actor launched a supply chain attack by injecting malicious JavaScript into the Okendo Reviews widget, which is used by over 18,000 brands. This compromise allowed the delivery of…
4 articles · Updated June 19, 2026 -
ClearFake Campaigns Utilize WordlistLoader to Distribute Amatera Infostealer
A new malware campaign identified as ClearFake employs a loader named WordlistLoader to deploy the Amatera infostealer, targeting Windows users. This loader reconstructs shellcode from encoded English words, enhancing…
3 articles · Updated August 21, 2026 -
ClearFake Campaign Uses Smart Contracts for C&C on BSC Testnet
In May 2026, TrendAI™ Research reported on a cyber intrusion involving the ClearFake campaign, where threat actors utilized the EtherHiding technique to deliver payloads via smart contracts on the BNB Smart Chain…
2 articles · Updated May 26, 2026 -
ClearFake Malware Campaign Exploits BSC Testnet for C2 Operations
The ClearFake campaign has emerged as a significant cybersecurity threat by using BNB Smart Chain (BSC) testnet smart contracts to establish a resilient command-and-control (C2) infrastructure. This innovative approach…
2 articles · Updated May 28, 2026 -
ClearFake Malware Campaign Uses Proxy Execution for PowerShell Attacks
The ClearFake malware campaign has evolved to exploit a command injection vulnerability in trusted Windows components, enabling the execution of malicious PowerShell commands. This sophisticated operation has…
2 articles · Updated January 22, 2026
Recent Intelligence Reports
- Hackers Hide Malware Code Inside English Words to Infect Windows Users — Cybersecuritynews · August 20, 2026
- Microsoft Warns Hackers Are Hiding Malware Commands Inside BNB Chain Smart Contracts — Finance.Biggo · August 7, 2026
- Microsoft warns hackers are using BNB Chain to spread malware — Altcoinbuzz · August 7, 2026
- Hackers Use BNB Chain Smart Contracts to Spread Malware via Fake CAPTCHAs — Kucoin · August 7, 2026
- Hackers exploit BNB Chain smart contracts to distribute malware via fake CAPTCHAs — Cryptobriefing · August 7, 2026
- Hackers Use BNB Chain to Spread Malware Through Fake CAPTCHAs — Decrypt.Co · August 7, 2026
- Microsoft Warns Hackers Are Using BNB Chain to Spread Malware — U.Today · August 6, 2026
- Smartapesg Returns With Unique Obfuscation Techniques — www.blumira.com · June 18, 2026