ClearFake Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
15
occurrences
First Seen
January 22, 2026
Last Seen
August 20, 2026

ClearFake is a malware family observed leveraging a proxy execution technique to run malicious PowerShell commands by abusing a Trusted Windows Feature.

Overview

ClearFake is a malware family observed leveraging a proxy execution technique to run malicious PowerShell commands by abusing a Trusted Windows Feature. This living-off-the-land approach uses legitimate Windows components to execute payloads, enabling stealthy operations and potential evasion of security controls.

Related Threat Clusters

Recent Intelligence Reports

  • Hackers Hide Malware Code Inside English Words to Infect Windows Users — Cybersecuritynews · August 20, 2026
  • Microsoft Warns Hackers Are Hiding Malware Commands Inside BNB Chain Smart Contracts — Finance.Biggo · August 7, 2026
  • Microsoft warns hackers are using BNB Chain to spread malware — Altcoinbuzz · August 7, 2026
  • Hackers Use BNB Chain Smart Contracts to Spread Malware via Fake CAPTCHAs — Kucoin · August 7, 2026
  • Hackers exploit BNB Chain smart contracts to distribute malware via fake CAPTCHAs — Cryptobriefing · August 7, 2026
  • Hackers Use BNB Chain to Spread Malware Through Fake CAPTCHAs — Decrypt.Co · August 7, 2026
  • Microsoft Warns Hackers Are Using BNB Chain to Spread Malware — U.Today · August 6, 2026
  • Smartapesg Returns With Unique Obfuscation Techniques — www.blumira.com · June 18, 2026

CVSS v3.1 Breakdown