#ClearFake
our last analysis of ClearFake ⤵️
blog.sekoia.io/clearfake-a-ne…
October 22, 2023 at 11:39 AM
ClearFake payload delivery endpoint in use within a day of its registration. Delivery: rehearsal-b[.]com/4qX0LB/tm/oPpE/. ClearFake reads its loader config from BNB Smart Chain contract storage (EtherHiding)
September 23, 2026 at 8:14 AM
🚨 ClearFake Malware Spreading Fast!

Hackers use fake reCAPTCHA & Cloudflare checks to deploy Lumma & Vidar Stealer malware.

🔹 9,300+ infected sites
🔹 200,000+ users exposed (July 2024)
🔹 Now using Binance Smart Chain for stealth #CyberAlerts #Malware thehackernews.com/2025/03/clea...
ClearFake Infects 9,300 Sites, Uses Fake reCAPTCHA and Turnstile to Spread Info-Stealers
ClearFake malware infects 9,300+ websites, using fake reCAPTCHA and Web3 tactics to spread Lumma and Vidar Stealers, exposing 200,000+ users.
thehackernews.com
March 19, 2025 at 9:44 PM
🚨 IOC Alert: ClearFake Payload Delivery Infrastructure

darkwebinformer.com/ioc-alert-cl...
IOC Alert: ClearFake Payload Delivery Infrastructure
IOC Alert: ClearFake Payload Delivery Infrastructure
darkwebinformer.com
September 18, 2025 at 6:00 PM
One of my good friends and former SOC protégé—dropping 🔥 analysis on a Monday afternoon. Epic work, @thecyber.dad 🚀

www.thecyber.dad/p/detecting-...
Detecting Fake CAPTCHA Campaigns: ClickFix, ClearFake, and Etherhide
Summary
www.thecyber.dad
April 22, 2025 at 1:01 AM
My latest blog post investigating a malware campaign which infects victims by utilizing only legitimate infrastructure. The malicious activity spans hundreds of hacked websites, the BSC blockchain, and a popular CDN.

expel.com/blog/clearfa...
ClearFake gets more evasive with new living off the land (LOTL) techniques
ClearFake's latest campaign uses fake CAPTCHAs and social engineering trick victims into installing malware, and it's getting more evasive.
expel.com
January 20, 2026 at 9:14 PM
2025-02-05 (Wednesday): #ClearFake / #ClickFix style fake CAPTCHA leads to possible #Vidar.

Vidar C2 using eteherealpath[.]top behind Cloudflare.

Details at github.com/malware-traf...
February 6, 2025 at 1:03 AM
Microsoft Threat Intelligence has identified a cluster of compromised websites displaying ClickFix lures and using EtherHiding, a technique associated with the ClearFake campaign.
August 6, 2026 at 4:17 PM
Here is our in-depth analysis of the latest #ClearFake variant using the Binance Smart Chain and two new ClickFix lures.

ClearFake is injected into thousands of compromised sites to distribute the #Emmental Loader, #Lumma, #Rhadamanthys, and #Vidar.

⬇️

bsky.app/profile/seko...
sekoia.com Sekoia @sekoia.com · Mar 19
TDR analysts published an analysis of the new #ClearFake variant that relies on compromised websites injected with the malicious JavaScript framework, the #EtherHiding technique, and the #ClickFix social engineering tactic.

buff.ly/vbiVbsN
ClearFake’s New Widespread Variant: Increased Web3 Exploitation for Malware Delivery
ClearFake spreads malware via compromised websites, using fake CAPTCHAs, JavaScript injections, and drive-by downloads.
blog.sekoia.io
March 20, 2025 at 6:50 PM
ClearFake Infects 9,300 Sites, Uses Fake reCAPTCHA and Turnstile to Spread Info-Stealers
thehackernews.com/2025/03/clea...
ClearFake Infects 9,300 Sites, Uses Fake reCAPTCHA and Turnstile to Spread Info-Stealers
ClearFake malware infects 9,300+ websites, using fake reCAPTCHA and Web3 tactics to spread Lumma and Vidar Stealers, exposing 200,000+ users.
thehackernews.com
March 19, 2025 at 12:36 PM
We added a feed of IPs/websites with ClickFix/ClearFake injected code in our Compromised Website reporting, tagged as 'clickfix'. Visitors of the website get tricked to install malware when injected JavaScript executes. If you receive an alert review for root cause of compromise!
March 15, 2026 at 4:06 PM
TDR analysts published an analysis of the new #ClearFake variant that relies on compromised websites injected with the malicious JavaScript framework, the #EtherHiding technique, and the #ClickFix social engineering tactic.

buff.ly/vbiVbsN
ClearFake’s New Widespread Variant: Increased Web3 Exploitation for Malware Delivery
ClearFake spreads malware via compromised websites, using fake CAPTCHAs, JavaScript injections, and drive-by downloads.
blog.sekoia.io
March 19, 2025 at 1:28 PM
October 23, 2023 at 6:48 AM
CAPTCHAgeddon is here. A fake CAPTCHA scam called ClickFix hijacks devices with a single paste—no download, no file, just clipboard commands.

It's smarter than ClearFake—and spreading fast. #Scam #CyberAlerts thehackernews.com/2025/08/clic...
ClickFix Malware Campaign Exploits CAPTCHAs to Spread Cross-Platform Infections
ClickFix malware replaced ClearFake in 2024, infecting users via fake CAPTCHAs and trusted platforms.
thehackernews.com
August 6, 2025 at 9:39 PM
#ClearFake variant is now spreading #Rhadamanthys Stealer via #Emmenhtal Loader.

cc @plebourhis.bsky.social @sekoia.io

1. ClearFake framework is injected on compromised WordPress and relies on EtherHiding

2. The #ClickFix lure uses a fake Cloudflare Turnstile with unusual web traffic

⬇️
March 6, 2025 at 10:50 AM
I had fun digging into fake CAPTCHA campaigns and shared some detections here: www.thecyber.dad/p/detecting-...
Detecting Fake CAPTCHA Campaigns: ClickFix, ClearFake, and Etherhide
Summary
www.thecyber.dad
April 22, 2025 at 12:59 AM
🚨 #macOS users beware! Atomic Stealer, a $1,000/month #malware, is now spreading through deceptive web browser updates via ClearFake.
thehackernews.com/2023/11/clea...
#cybersecurity #informationsecurity
ClearFake Campaign Expands to Target Mac Systems with Atomic Stealer
macOS users beware! Atomic Stealer, a $1,000/month malware, is now spreading through deceptive web browser updates via ClearFake.
thehackernews.com
November 22, 2023 at 12:48 PM
657 instances shared for 2026-03-14. We expect to increase the volume of the feed in the future!

We would like to thank our Alliance partners and Validin for the collaboration making this possible!

Background on investigating ClickFix/ClearFake: www.atea.no/siste-nytt/i...
Investigating a ClearFake/ClickFix + Etherhide campaign
We have identified and tracked a new campaign utilizing ClearFake and EtherHiding technique. This infects legitimate websites resulting in information stealer.
www.atea.no
March 15, 2026 at 4:06 PM
👀 The domain saaadnesss[.]shop registered a month ago used to track infected victims in a Fake Captcha /ClickFix/Clearfake campaign is now already being seen as one of the top 1 million domains as a result of being served from compromised websites.

urlscan.io/search/#saaa...
December 23, 2024 at 2:07 AM
#ClearFake / #ClickFix is back infecting directly legit but vulnerable websites, delivering in the end #Lumma / #LummaStealer
January 6, 2025 at 8:51 PM
What is old is new again, #atomicstealer being distributed via #clearfake campaign. Haven't seen that in a while!

Clearfake domain: cejecuu4[.]xyz
C2: 193.124.185[.]23

Payload staged in Dropbox

#macosmalware #infostealers #amos #fakebrowserupdates #fakechrome
August 6, 2024 at 7:08 AM
ClearFake Infects 9,300 Sites, Uses Fake reCAPTCHA and Turnstile to Spread Info-Stealers #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
March 19, 2025 at 4:35 PM
I would have expected EtherHiding to be more popular, but two years later, it's just ClearFake, a botnet I haven't heard anything about in ages, and now some North Korean hackers

cloud.google.com/blog/topics/...
DPRK Adopts EtherHiding: Nation-State Malware Hiding on Blockchains | Google Cloud Blog
North Korea threat actor UNC5342 is leveraging the EtherHiding technique in espionage and financially motivated operations.
cloud.google.com
October 16, 2025 at 3:01 PM
📢 Expel décrit une évolution de ClearFake/ClickFix qui héberge ses charges via des smart contracts
📝 Source et contexte: Expel (blog, Mar…
https://cyberveille.ch/posts/2026-01-22-expel-decrit-une-evolution-de-clearfake-clickfix-qui-heberge-ses-charges-via-des-smart-contracts/ #ClearFake #Cyberveille
January 23, 2026 at 4:00 PM