ClearFake is a malware family tracked across 5 threat clusters and 8 intelligence report mentions on ThreatCluster. First observed January 22, 2026; most recent activity June 18, 2026.
ClearFake is a malware family observed leveraging a proxy execution technique to run malicious PowerShell commands by abusing a Trusted Windows Feature. This living-off-the-land approach uses legitimate Windows components to execute payloads, enabling stealthy operations and potential evasion of security controls.
The Google Threat Intelligence Group (GTIG) reports that North Korean threat actor UNC5342 has adopted a new technique called EtherHiding to deliver malware and facilitate cryptocurrency theft. This method embeds…
On May 14, 2026, the SmartApeSG threat actor launched a supply chain attack by injecting malicious JavaScript into the Okendo Reviews widget, which is used by over 18,000 brands. This compromise allowed the delivery of…
In May 2026, TrendAI™ Research reported on a cyber intrusion involving the ClearFake campaign, where threat actors utilized the EtherHiding technique to deliver payloads via smart contracts on the BNB Smart Chain…
The ClearFake campaign has emerged as a significant cybersecurity threat by using BNB Smart Chain (BSC) testnet smart contracts to establish a resilient command-and-control (C2) infrastructure. This innovative approach…
The ClearFake malware campaign has evolved to exploit a command injection vulnerability in trusted Windows components, enabling the execution of malicious PowerShell commands. This sophisticated operation has…