home.social

#clearfake — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #clearfake, aggregated by home.social.

fetched live
  1. WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords

    Indicators extracted from public reporting. Source: gendigital.com/blog/insights/r

    Pulse ID: 6a8c4d5527ae029719473a8b
    Pulse Link: otx.alienvault.com/pulse/6a8c4
    Pulse Author: CyberHunter_NL
    Created: 2026-08-24 13:55:33

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ClearFake #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Password #Passwords #RCE #Windows #Word #bot #CyberHunter_NL

  2. WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords

    Indicators extracted from public reporting. Source: gendigital.com/blog/insights/r

    Pulse ID: 6a8c4d5527ae029719473a8b
    Pulse Link: otx.alienvault.com/pulse/6a8c4
    Pulse Author: CyberHunter_NL
    Created: 2026-08-24 13:55:33

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ClearFake #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Password #Passwords #RCE #Windows #Word #bot #CyberHunter_NL

  3. WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords

    Indicators extracted from public reporting. Source: gendigital.com/blog/insights/r

    Pulse ID: 6a8c4d5527ae029719473a8b
    Pulse Link: otx.alienvault.com/pulse/6a8c4
    Pulse Author: CyberHunter_NL
    Created: 2026-08-24 13:55:33

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ClearFake #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Password #Passwords #RCE #Windows #Word #bot #CyberHunter_NL

  4. WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords

    Indicators extracted from public reporting. Source: gendigital.com/blog/insights/r

    Pulse ID: 6a8c4d5527ae029719473a8b
    Pulse Link: otx.alienvault.com/pulse/6a8c4
    Pulse Author: CyberHunter_NL
    Created: 2026-08-24 13:55:33

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ClearFake #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Password #Passwords #RCE #Windows #Word #bot #CyberHunter_NL

  5. WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords

    Indicators extracted from public reporting. Source: gendigital.com/blog/insights/r

    Pulse ID: 6a8c4d5527ae029719473a8b
    Pulse Link: otx.alienvault.com/pulse/6a8c4
    Pulse Author: CyberHunter_NL
    Created: 2026-08-24 13:55:33

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ClearFake #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Password #Passwords #RCE #Windows #Word #bot #CyberHunter_NL

  6. Hackers Hide Malware Code Inside English Words to Infect Windows Users

    Indicators extracted from public reporting. Source: gendigital.com/blog/insights/r

    Pulse ID: 6a86f988170e8cbccf5ad369
    Pulse Link: otx.alienvault.com/pulse/6a86f
    Pulse Author: CyberHunter_NL
    Created: 2026-08-20 12:56:40

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ClearFake #CyberSecurity #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #Windows #Word #bot #CyberHunter_NL

  7. Hackers Hide Malware Code Inside English Words to Infect Windows Users

    Indicators extracted from public reporting. Source: gendigital.com/blog/insights/r

    Pulse ID: 6a86f988170e8cbccf5ad369
    Pulse Link: otx.alienvault.com/pulse/6a86f
    Pulse Author: CyberHunter_NL
    Created: 2026-08-20 12:56:40

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ClearFake #CyberSecurity #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #Windows #Word #bot #CyberHunter_NL

  8. Hackers Hide Malware Code Inside English Words to Infect Windows Users

    Indicators extracted from public reporting. Source: gendigital.com/blog/insights/r

    Pulse ID: 6a86f988170e8cbccf5ad369
    Pulse Link: otx.alienvault.com/pulse/6a86f
    Pulse Author: CyberHunter_NL
    Created: 2026-08-20 12:56:40

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ClearFake #CyberSecurity #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #Windows #Word #bot #CyberHunter_NL

  9. Hackers Hide Malware Code Inside English Words to Infect Windows Users

    Indicators extracted from public reporting. Source: gendigital.com/blog/insights/r

    Pulse ID: 6a86f988170e8cbccf5ad369
    Pulse Link: otx.alienvault.com/pulse/6a86f
    Pulse Author: CyberHunter_NL
    Created: 2026-08-20 12:56:40

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ClearFake #CyberSecurity #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #Windows #Word #bot #CyberHunter_NL

  10. Hackers Hide Malware Code Inside English Words to Infect Windows Users

    Indicators extracted from public reporting. Source: gendigital.com/blog/insights/r

    Pulse ID: 6a86f988170e8cbccf5ad369
    Pulse Link: otx.alienvault.com/pulse/6a86f
    Pulse Author: CyberHunter_NL
    Created: 2026-08-20 12:56:40

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ClearFake #CyberSecurity #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #Windows #Word #bot #CyberHunter_NL

  11. 📢 Dropcatch : trois acteurs scavengers recyclent des domaines malveillants expirés pour monétiser du trafic

    📅 Source : Infoblox Threat Intelligence, publié le 13 août 2026. Il s'agit de la troisième partie d'une série de blogs sur la pratique du dropcatch de domaines malveillants. Chaque année, des dizaines de milliers de sites web sont compromis par…

    📖 cyberveille : cyberveille.ch/posts/2026-08-1
    🌐 source : infoblox.com/blog/threat-intel
    🟢 vérification factuelle haute
    #dropcatch #ClearFake #Cyberveille

  12. .ru serious? 🇷🇺 ccTLD .ru had an unbelievable +3741% ⏫ in #botnet C&C domains, placing it #1 for the most abused ccTLD in the latter half of 2025. This activity can be attributed almost entirely to #clearfake, a malicious JavaScript framework.

    Learn more in the Botnet Threat Update Jul - Dec 2025 ⤵️ ⤵️
    spamhaus.org/resource-hub/botn

    #ccTLD #BotnetCC #ThreatIntel

  13. .ru serious? 🇷🇺 ccTLD .ru had an unbelievable +3741% ⏫ in #botnet C&C domains, placing it #1 for the most abused ccTLD in the latter half of 2025. This activity can be attributed almost entirely to #clearfake, a malicious JavaScript framework.

    Learn more in the Botnet Threat Update Jul - Dec 2025 ⤵️ ⤵️
    spamhaus.org/resource-hub/botn

    #ccTLD #BotnetCC #ThreatIntel

  14. .ru serious? 🇷🇺 ccTLD .ru had an unbelievable +3741% ⏫ in #botnet C&C domains, placing it #1 for the most abused ccTLD in the latter half of 2025. This activity can be attributed almost entirely to #clearfake, a malicious JavaScript framework.

    Learn more in the Botnet Threat Update Jul - Dec 2025 ⤵️ ⤵️
    spamhaus.org/resource-hub/botn

    #ccTLD #BotnetCC #ThreatIntel

  15. .ru serious? 🇷🇺 ccTLD .ru had an unbelievable +3741% ⏫ in #botnet C&C domains, placing it #1 for the most abused ccTLD in the latter half of 2025. This activity can be attributed almost entirely to #clearfake, a malicious JavaScript framework.

    Learn more in the Botnet Threat Update Jul - Dec 2025 ⤵️ ⤵️
    spamhaus.org/resource-hub/botn

    #ccTLD #BotnetCC #ThreatIntel

  16. .ru serious? 🇷🇺 ccTLD .ru had an unbelievable +3741% ⏫ in #botnet C&C domains, placing it #1 for the most abused ccTLD in the latter half of 2025. This activity can be attributed almost entirely to #clearfake, a malicious JavaScript framework.

    Learn more in the Botnet Threat Update Jul - Dec 2025 ⤵️ ⤵️
    spamhaus.org/resource-hub/botn

    #ccTLD #BotnetCC #ThreatIntel

  17. 🚨 ClearFake Payload Delivery Domain Identified

    A domain linked to ClearFake activity has been flagged delivering a js.clearfake payload with 100% confidence.

    Quick Facts:

    ▪️Type: Domain
    ▪️Indicator: x5ust[.]windshift[.]ru
    ▪️Threat Type: Payload Delivery
    ▪️Malware: js.clearfake
    ▪️Date: 05 Dec 2025 // 00:17 UTC
    ▪️Tags: #ClearFake
    ▪️Reporter: threatcat_ch

    URLScan:

    ▪️Verdict: 0
    ▪️Title: FASTPANEL
    ▪️Domain: urlscan.io/domain/x5ust.windsh
    ▪️Result: urlscan.io/result/019aebe2-3c7
    ▪️Screenshot: urlscan.io/screenshots/019aebe

    DNS / CT Data:

    ▪️A Records: 104.21.19.50, 172.67.185.61
    ▪️DNSlytics: dnslytics.com/domain/x5ust.win

    Related Intelligence:

    ▪️CRT: crt.sh/?q=x5ust.windshift.ru
    ▪️VirusTotal: virustotal.com/gui/domain/x5us

  18. 🚨 ClearFake Payload Delivery Domain Identified

    A domain linked to ClearFake activity has been flagged delivering a js.clearfake payload with 100% confidence.

    Quick Facts:

    ▪️Type: Domain
    ▪️Indicator: x5ust[.]windshift[.]ru
    ▪️Threat Type: Payload Delivery
    ▪️Malware: js.clearfake
    ▪️Date: 05 Dec 2025 // 00:17 UTC
    ▪️Tags: #ClearFake
    ▪️Reporter: threatcat_ch

    URLScan:

    ▪️Verdict: 0
    ▪️Title: FASTPANEL
    ▪️Domain: urlscan.io/domain/x5ust.windsh
    ▪️Result: urlscan.io/result/019aebe2-3c7
    ▪️Screenshot: urlscan.io/screenshots/019aebe

    DNS / CT Data:

    ▪️A Records: 104.21.19.50, 172.67.185.61
    ▪️DNSlytics: dnslytics.com/domain/x5ust.win

    Related Intelligence:

    ▪️CRT: crt.sh/?q=x5ust.windshift.ru
    ▪️VirusTotal: virustotal.com/gui/domain/x5us

  19. 🚨 ClearFake Payload Delivery Domain Identified

    A domain linked to ClearFake activity has been flagged delivering a js.clearfake payload with 100% confidence.

    Quick Facts:

    ▪️Type: Domain
    ▪️Indicator: x5ust[.]windshift[.]ru
    ▪️Threat Type: Payload Delivery
    ▪️Malware: js.clearfake
    ▪️Date: 05 Dec 2025 // 00:17 UTC
    ▪️Tags: #ClearFake
    ▪️Reporter: threatcat_ch

    URLScan:

    ▪️Verdict: 0
    ▪️Title: FASTPANEL
    ▪️Domain: urlscan.io/domain/x5ust.windsh
    ▪️Result: urlscan.io/result/019aebe2-3c7
    ▪️Screenshot: urlscan.io/screenshots/019aebe

    DNS / CT Data:

    ▪️A Records: 104.21.19.50, 172.67.185.61
    ▪️DNSlytics: dnslytics.com/domain/x5ust.win

    Related Intelligence:

    ▪️CRT: crt.sh/?q=x5ust.windshift.ru
    ▪️VirusTotal: virustotal.com/gui/domain/x5us

  20. 🚨 ClearFake Payload Delivery Domain Identified

    A domain linked to ClearFake activity has been flagged delivering a js.clearfake payload with 100% confidence.

    Quick Facts:

    ▪️Type: Domain
    ▪️Indicator: x5ust[.]windshift[.]ru
    ▪️Threat Type: Payload Delivery
    ▪️Malware: js.clearfake
    ▪️Date: 05 Dec 2025 // 00:17 UTC
    ▪️Tags: #ClearFake
    ▪️Reporter: threatcat_ch

    URLScan:

    ▪️Verdict: 0
    ▪️Title: FASTPANEL
    ▪️Domain: urlscan.io/domain/x5ust.windsh
    ▪️Result: urlscan.io/result/019aebe2-3c7
    ▪️Screenshot: urlscan.io/screenshots/019aebe

    DNS / CT Data:

    ▪️A Records: 104.21.19.50, 172.67.185.61
    ▪️DNSlytics: dnslytics.com/domain/x5ust.win

    Related Intelligence:

    ▪️CRT: crt.sh/?q=x5ust.windshift.ru
    ▪️VirusTotal: virustotal.com/gui/domain/x5us

  21. 🚨 ClearFake Payload Delivery Domain Identified

    A domain linked to ClearFake activity has been flagged delivering a js.clearfake payload with 100% confidence.

    Quick Facts:

    ▪️Type: Domain
    ▪️Indicator: x5ust[.]windshift[.]ru
    ▪️Threat Type: Payload Delivery
    ▪️Malware: js.clearfake
    ▪️Date: 05 Dec 2025 // 00:17 UTC
    ▪️Tags: #ClearFake
    ▪️Reporter: threatcat_ch

    URLScan:

    ▪️Verdict: 0
    ▪️Title: FASTPANEL
    ▪️Domain: urlscan.io/domain/x5ust.windsh
    ▪️Result: urlscan.io/result/019aebe2-3c7
    ▪️Screenshot: urlscan.io/screenshots/019aebe

    DNS / CT Data:

    ▪️A Records: 104.21.19.50, 172.67.185.61
    ▪️DNSlytics: dnslytics.com/domain/x5ust.win

    Related Intelligence:

    ▪️CRT: crt.sh/?q=x5ust.windshift.ru
    ▪️VirusTotal: virustotal.com/gui/domain/x5us

  22. 🚨 New malware variant: ClickFix

    Guardio Labs reveals a ClearFake mutation that skips downloads and uses fake CAPTCHAs to get users to paste malware into Run or Terminal.
    ▪️ Cross-platform
    ▪️ Google Scripts abused
    ▪️ Hosted payloads in JS files
    ▪️ SEO & drive-by lures

    “A chilling list of techniques…” — Shaked Chen

    #clickfix #ClearFake #CAPTCHAgeddon #Malware #GuardioLabs #CyberThreat #Infosec #MastodonSec

  23. 🚨 New malware variant: ClickFix

    Guardio Labs reveals a ClearFake mutation that skips downloads and uses fake CAPTCHAs to get users to paste malware into Run or Terminal.
    ▪️ Cross-platform
    ▪️ Google Scripts abused
    ▪️ Hosted payloads in JS files
    ▪️ SEO & drive-by lures

    “A chilling list of techniques…” — Shaked Chen

    #clickfix #ClearFake #CAPTCHAgeddon #Malware #GuardioLabs #CyberThreat #Infosec #MastodonSec

  24. TDR analysts published an analysis of the new #ClearFake variant that relies on compromised websites injected with the malicious JavaScript framework, the #EtherHiding technique, and the #ClickFix social engineering tactic.

    blog.sekoia.io/clearfakes-new-

  25. TDR analysts published an analysis of the new #ClearFake variant that relies on compromised websites injected with the malicious JavaScript framework, the #EtherHiding technique, and the #ClickFix social engineering tactic.

    blog.sekoia.io/clearfakes-new-

  26. TDR analysts published an analysis of the new #ClearFake variant that relies on compromised websites injected with the malicious JavaScript framework, the #EtherHiding technique, and the #ClickFix social engineering tactic.

    blog.sekoia.io/clearfakes-new-

  27. TDR analysts published an analysis of the new #ClearFake variant that relies on compromised websites injected with the malicious JavaScript framework, the #EtherHiding technique, and the #ClickFix social engineering tactic.

    blog.sekoia.io/clearfakes-new-

  28. TDR analysts published an analysis of the new #ClearFake variant that relies on compromised websites injected with the malicious JavaScript framework, the #EtherHiding technique, and the #ClickFix social engineering tactic.

    blog.sekoia.io/clearfakes-new-

  29. Whenever you run something inside a Windows Run dialog box, apparently it gets saved to the registry under the RunMRU key.
    This can be helpful for those of you hunting for ClickFix / ClearFake campaign activity since anything executed after the run dialog has a better chance of blending into benign activity.
    Building regex patterns on the registry key values can help uncover any malicious commands with multiple arguments.

    #clickfix #clearfake #threathunting
    forensafe.com/blogs/runmrukey.

  30. Whenever you run something inside a Windows Run dialog box, apparently it gets saved to the registry under the RunMRU key.
    This can be helpful for those of you hunting for ClickFix / ClearFake campaign activity since anything executed after the run dialog has a better chance of blending into benign activity.
    Building regex patterns on the registry key values can help uncover any malicious commands with multiple arguments.

    #clickfix #clearfake #threathunting
    forensafe.com/blogs/runmrukey.

  31. Whenever you run something inside a Windows Run dialog box, apparently it gets saved to the registry under the RunMRU key.
    This can be helpful for those of you hunting for ClickFix / ClearFake campaign activity since anything executed after the run dialog has a better chance of blending into benign activity.
    Building regex patterns on the registry key values can help uncover any malicious commands with multiple arguments.

    #clickfix #clearfake #threathunting
    forensafe.com/blogs/runmrukey.

  32. Whenever you run something inside a Windows Run dialog box, apparently it gets saved to the registry under the RunMRU key.
    This can be helpful for those of you hunting for ClickFix / ClearFake campaign activity since anything executed after the run dialog has a better chance of blending into benign activity.
    Building regex patterns on the registry key values can help uncover any malicious commands with multiple arguments.

    #clickfix #clearfake #threathunting
    forensafe.com/blogs/runmrukey.

  33. Whenever you run something inside a Windows Run dialog box, apparently it gets saved to the registry under the RunMRU key.
    This can be helpful for those of you hunting for ClickFix / ClearFake campaign activity since anything executed after the run dialog has a better chance of blending into benign activity.
    Building regex patterns on the registry key values can help uncover any malicious commands with multiple arguments.

    #clickfix #clearfake #threathunting
    forensafe.com/blogs/runmrukey.

  34. While investigating an infected website, we noticed call to BSC testnet contract 0x0967296defa0fd586c9ede5730380e2b059fab95 : testnet.bscscan.com/address/0x

    The contract’s content is clearly malicious and connects over WebSocket to suckerity[.]xyz (behind Cloudflare), not related to #ClearFake, but reminds us #Magecart related injections:

  35. While investigating an infected website, we noticed call to BSC testnet contract 0x0967296defa0fd586c9ede5730380e2b059fab95 : testnet.bscscan.com/address/0x

    The contract’s content is clearly malicious and connects over WebSocket to suckerity[.]xyz (behind Cloudflare), not related to #ClearFake, but reminds us #Magecart related injections:

  36. While investigating an infected website, we noticed call to BSC testnet contract 0x0967296defa0fd586c9ede5730380e2b059fab95 : testnet.bscscan.com/address/0x

    The contract’s content is clearly malicious and connects over WebSocket to suckerity[.]xyz (behind Cloudflare), not related to #ClearFake, but reminds us #Magecart related injections:

  37. While investigating an infected website, we noticed call to BSC testnet contract 0x0967296defa0fd586c9ede5730380e2b059fab95 : testnet.bscscan.com/address/0x

    The contract’s content is clearly malicious and connects over WebSocket to suckerity[.]xyz (behind Cloudflare), not related to #ClearFake, but reminds us #Magecart related injections:

  38. While investigating an infected website, we noticed call to BSC testnet contract 0x0967296defa0fd586c9ede5730380e2b059fab95 : testnet.bscscan.com/address/0x

    The contract’s content is clearly malicious and connects over WebSocket to suckerity[.]xyz (behind Cloudflare), not related to #ClearFake, but reminds us #Magecart related injections:

  39. #etherhiding (hiding malicious code in blockchain based smart contracts) is not only by #ClearFake related actors – but now also for #Magecart 👇

  40. #etherhiding (hiding malicious code in blockchain based smart contracts) is not only by #ClearFake related actors – but now also for #Magecart 👇

  41. #etherhiding (hiding malicious code in blockchain based smart contracts) is not only by #ClearFake related actors – but now also for #Magecart 👇

  42. #etherhiding (hiding malicious code in blockchain based smart contracts) is not only by #ClearFake related actors – but now also for #Magecart 👇