ClearFake Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
8
occurrences
First Seen
January 22, 2026
Last Seen
June 18, 2026

ClearFake is a malware family tracked across 5 threat clusters and 8 intelligence report mentions on ThreatCluster. First observed January 22, 2026; most recent activity June 18, 2026.

Overview

ClearFake is a malware family observed leveraging a proxy execution technique to run malicious PowerShell commands by abusing a Trusted Windows Feature. This living-off-the-land approach uses legitimate Windows components to execute payloads, enabling stealthy operations and potential evasion of security controls.

Related Threat Clusters

Recent Intelligence Reports

  • Smartapesg Returns With Unique Obfuscation Techniques — www.blumira.com · June 18, 2026
  • ClearFake Uses BSC Testnet Smart Contracts for Takedown — Cybersecuritynews · May 28, 2026
  • ClearFake Abuses BSC Testnet Contracts for Resilient C2 Operations — Gbhackers · May 28, 2026
  • Etherhiding Hiding Web2 Malicious Code In Web3 Smart Contracts 65ea78efad16 — labs.guard.io · May 26, 2026
  • Dprk Adopts Etherhiding — cloud.google.com · May 26, 2026
  • Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet — Trendmicro · May 26, 2026
  • Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet — Feeds.Trendmicro · May 26, 2026
  • ClearFake malware Exploits Proxy Execution to Run Malicious PowerShell Commands via Trusted Windows Feature — Gbhackers · January 22, 2026

CVSS v3.1 Breakdown