home.social

#clearfake — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #clearfake, aggregated by home.social.

fetched live
  1. WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords

    Indicators extracted from public reporting. Source: gendigital.com/blog/insights/r

    Pulse ID: 6a8c4d5527ae029719473a8b
    Pulse Link: otx.alienvault.com/pulse/6a8c4
    Pulse Author: CyberHunter_NL
    Created: 2026-08-24 13:55:33

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ClearFake #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Password #Passwords #RCE #Windows #Word #bot #CyberHunter_NL

  2. Hackers Hide Malware Code Inside English Words to Infect Windows Users

    Indicators extracted from public reporting. Source: gendigital.com/blog/insights/r

    Pulse ID: 6a86f988170e8cbccf5ad369
    Pulse Link: otx.alienvault.com/pulse/6a86f
    Pulse Author: CyberHunter_NL
    Created: 2026-08-20 12:56:40

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ClearFake #CyberSecurity #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #Windows #Word #bot #CyberHunter_NL

  3. .ru serious? 🇷🇺 ccTLD .ru had an unbelievable +3741% ⏫ in #botnet C&C domains, placing it #1 for the most abused ccTLD in the latter half of 2025. This activity can be attributed almost entirely to #clearfake, a malicious JavaScript framework.

    Learn more in the Botnet Threat Update Jul - Dec 2025 ⤵️ ⤵️
    spamhaus.org/resource-hub/botn

    #ccTLD #BotnetCC #ThreatIntel

  4. 🚨 ClearFake Payload Delivery Domain Identified

    A domain linked to ClearFake activity has been flagged delivering a js.clearfake payload with 100% confidence.

    Quick Facts:

    ▪️Type: Domain
    ▪️Indicator: x5ust[.]windshift[.]ru
    ▪️Threat Type: Payload Delivery
    ▪️Malware: js.clearfake
    ▪️Date: 05 Dec 2025 // 00:17 UTC
    ▪️Tags: #ClearFake
    ▪️Reporter: threatcat_ch

    URLScan:

    ▪️Verdict: 0
    ▪️Title: FASTPANEL
    ▪️Domain: urlscan.io/domain/x5ust.windsh
    ▪️Result: urlscan.io/result/019aebe2-3c7
    ▪️Screenshot: urlscan.io/screenshots/019aebe

    DNS / CT Data:

    ▪️A Records: 104.21.19.50, 172.67.185.61
    ▪️DNSlytics: dnslytics.com/domain/x5ust.win

    Related Intelligence:

    ▪️CRT: crt.sh/?q=x5ust.windshift.ru
    ▪️VirusTotal: virustotal.com/gui/domain/x5us

  5. TDR analysts published an analysis of the new #ClearFake variant that relies on compromised websites injected with the malicious JavaScript framework, the #EtherHiding technique, and the #ClickFix social engineering tactic.

    blog.sekoia.io/clearfakes-new-

  6. Whenever you run something inside a Windows Run dialog box, apparently it gets saved to the registry under the RunMRU key.
    This can be helpful for those of you hunting for ClickFix / ClearFake campaign activity since anything executed after the run dialog has a better chance of blending into benign activity.
    Building regex patterns on the registry key values can help uncover any malicious commands with multiple arguments.

    #clickfix #clearfake #threathunting
    forensafe.com/blogs/runmrukey.

  7. While investigating an infected website, we noticed call to BSC testnet contract 0x0967296defa0fd586c9ede5730380e2b059fab95 : testnet.bscscan.com/address/0x

    The contract’s content is clearly malicious and connects over WebSocket to suckerity[.]xyz (behind Cloudflare), not related to #ClearFake, but reminds us #Magecart related injections:

  8. #etherhiding (hiding malicious code in blockchain based smart contracts) is not only by #ClearFake related actors – but now also for #Magecart 👇

  9. Вредоносный код навсегда сохранили в блокчейне

    Один из старых хакерских трюков — распространять вредоносное ПО под видом обновления браузера . На взломанном сайте размещается плашка с утверждением, что для просмотра нужно обновить браузер. И кнопка для скачивания обновления, как на скриншоте с прошлогодней атаки ClearFake . Таким образом, жертва самостоятельно устанавливает вредоносное ПО на свой компьютер. В прошлом году злоумышленники разработали умный способ защитить вредоносный софт от уничтожения. Они разместили его в децентрализованном анонимном блокчейне . То есть интегрировали код в смарт-контракт, который навечно сохранился в открытом доступе.

    habr.com/ru/companies/globalsi

    #блокчейн #обновление_браузера #BSC #Binance_Smart_Chain #Binance #BNB #WordPress #ClearFake #BscScan #EtherHiding

  10. #ClearFake / #ClickFix is back infecting directly legit but vulnerable websites, delivering in the end #Lumma / #LummaStealer

  11. New Swiss centered malware campaign in German using some #ClearFake / #ClickFix tricks impersonating Ricardo, one of the biggest Swiss online second-hand marketplace:

  12. @monitorsg #ClearFake is back to fake browser updates. The EXE leads to a Lumma stealer that appears to use these domains.

    predatowpmn[.]shop
    preachstrwnwjw[.]shop
    pang-scrooge-carnage[.]shop

    h/t @GustyDusty

  13. Sometimes people ask us to remove a domain from our blocklists that are part of a malicious traffic distribution system (TDS) because they "visited the url" and didn't get malware. This is like saying "I walked past the armed robber and didn't get robbed." Count yourself lucky. Say no to TDS. #dns #threatintel #cybercrime #malware #phishing #scam #infoblox #cybersecurity #infosec #tds #vextrio #socgholish #clearfake #404tds #adware

  14. #ClearFake related contract 0xa6165aa33ac710ad5dcd4f4d6379466825476fde was updated recently and points now to daslkjfhi2[.]lol, displaying a new type of lure to visitors: