#clearfake — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #clearfake, aggregated by home.social.
-
-
-
Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet
#Clearfake #ACRStealer
https://www.trendmicro.com/en_us/research/26/e/smart-contracts-for-command-and-control.html -
Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet
#Clearfake #ACRStealer
https://www.trendmicro.com/en_us/research/26/e/smart-contracts-for-command-and-control.html -
.ru serious? 🇷🇺 ccTLD .ru had an unbelievable +3741% ⏫ in #botnet C&C domains, placing it #1 for the most abused ccTLD in the latter half of 2025. This activity can be attributed almost entirely to #clearfake, a malicious JavaScript framework.
Learn more in the Botnet Threat Update Jul - Dec 2025 ⤵️ ⤵️
https://www.spamhaus.org/resource-hub/botnet-c-c/botnet-threat-update-july-to-december-2025/ -
.ru serious? 🇷🇺 ccTLD .ru had an unbelievable +3741% ⏫ in #botnet C&C domains, placing it #1 for the most abused ccTLD in the latter half of 2025. This activity can be attributed almost entirely to #clearfake, a malicious JavaScript framework.
Learn more in the Botnet Threat Update Jul - Dec 2025 ⤵️ ⤵️
https://www.spamhaus.org/resource-hub/botnet-c-c/botnet-threat-update-july-to-december-2025/ -
ClearFake gets more evasive with new living off the land (LOTL) techniques
#Clearfake
https://expel.com/blog/clearfake-new-lotl-techniques/ -
ClearFake gets more evasive with new living off the land (LOTL) techniques
#Clearfake
https://expel.com/blog/clearfake-new-lotl-techniques/ -
🚨 ClearFake Payload Delivery Domain Identified
A domain linked to ClearFake activity has been flagged delivering a js.clearfake payload with 100% confidence.
Quick Facts:
▪️Type: Domain
▪️Indicator: x5ust[.]windshift[.]ru
▪️Threat Type: Payload Delivery
▪️Malware: js.clearfake
▪️Date: 05 Dec 2025 // 00:17 UTC
▪️Tags: #ClearFake
▪️Reporter: threatcat_chURLScan:
▪️Verdict: 0
▪️Title: FASTPANEL
▪️Domain: https://urlscan.io/domain/x5ust.windshift.ru
▪️Result: https://urlscan.io/result/019aebe2-3c71-77ff-9e6d-5d225679e78a/
▪️Screenshot: https://urlscan.io/screenshots/019aebe2-3c71-77ff-9e6d-5d225679e78a.pngDNS / CT Data:
▪️A Records: 104.21.19.50, 172.67.185.61
▪️DNSlytics: https://dnslytics.com/domain/x5ust.windshift.ruRelated Intelligence:
▪️CRT: https://crt.sh/?q=x5ust.windshift.ru
▪️VirusTotal: https://www.virustotal.com/gui/domain/x5ust.windshift.ru -
🚨 ClearFake Payload Delivery Domain Identified
A domain linked to ClearFake activity has been flagged delivering a js.clearfake payload with 100% confidence.
Quick Facts:
▪️Type: Domain
▪️Indicator: x5ust[.]windshift[.]ru
▪️Threat Type: Payload Delivery
▪️Malware: js.clearfake
▪️Date: 05 Dec 2025 // 00:17 UTC
▪️Tags: #ClearFake
▪️Reporter: threatcat_chURLScan:
▪️Verdict: 0
▪️Title: FASTPANEL
▪️Domain: https://urlscan.io/domain/x5ust.windshift.ru
▪️Result: https://urlscan.io/result/019aebe2-3c71-77ff-9e6d-5d225679e78a/
▪️Screenshot: https://urlscan.io/screenshots/019aebe2-3c71-77ff-9e6d-5d225679e78a.pngDNS / CT Data:
▪️A Records: 104.21.19.50, 172.67.185.61
▪️DNSlytics: https://dnslytics.com/domain/x5ust.windshift.ruRelated Intelligence:
▪️CRT: https://crt.sh/?q=x5ust.windshift.ru
▪️VirusTotal: https://www.virustotal.com/gui/domain/x5ust.windshift.ru -
TDR analysts published an analysis of the new #ClearFake variant that relies on compromised websites injected with the malicious JavaScript framework, the #EtherHiding technique, and the #ClickFix social engineering tactic.
-
TDR analysts published an analysis of the new #ClearFake variant that relies on compromised websites injected with the malicious JavaScript framework, the #EtherHiding technique, and the #ClickFix social engineering tactic.
-
Whenever you run something inside a Windows Run dialog box, apparently it gets saved to the registry under the RunMRU key.
This can be helpful for those of you hunting for ClickFix / ClearFake campaign activity since anything executed after the run dialog has a better chance of blending into benign activity.
Building regex patterns on the registry key values can help uncover any malicious commands with multiple arguments.#clickfix #clearfake #threathunting
https://forensafe.com/blogs/runmrukey.html -
Whenever you run something inside a Windows Run dialog box, apparently it gets saved to the registry under the RunMRU key.
This can be helpful for those of you hunting for ClickFix / ClearFake campaign activity since anything executed after the run dialog has a better chance of blending into benign activity.
Building regex patterns on the registry key values can help uncover any malicious commands with multiple arguments.#clickfix #clearfake #threathunting
https://forensafe.com/blogs/runmrukey.html -
While investigating an infected website, we noticed call to BSC testnet contract 0x0967296defa0fd586c9ede5730380e2b059fab95 : https://testnet.bscscan.com/address/0x0967296defa0fd586c9ede5730380e2b059fab95
The contract’s content is clearly malicious and connects over WebSocket to suckerity[.]xyz (behind Cloudflare), not related to #ClearFake, but reminds us #Magecart related injections:
-
While investigating an infected website, we noticed call to BSC testnet contract 0x0967296defa0fd586c9ede5730380e2b059fab95 : https://testnet.bscscan.com/address/0x0967296defa0fd586c9ede5730380e2b059fab95
The contract’s content is clearly malicious and connects over WebSocket to suckerity[.]xyz (behind Cloudflare), not related to #ClearFake, but reminds us #Magecart related injections:
-
#etherhiding (hiding malicious code in blockchain based smart contracts) is not only by #ClearFake related actors – but now also for #Magecart 👇
-
#etherhiding (hiding malicious code in blockchain based smart contracts) is not only by #ClearFake related actors – but now also for #Magecart 👇
-
2025-02-05 (Wednesday): #ClearFake / #ClickFix style fake CAPTCHA leads to possible #Vidar.
Vidar C2 using eteherealpath[.]top behind Cloudflare.
-
2025-02-05 (Wednesday): #ClearFake / #ClickFix style fake CAPTCHA leads to possible #Vidar.
Vidar C2 using eteherealpath[.]top behind Cloudflare.
-
Вредоносный код навсегда сохранили в блокчейне
Один из старых хакерских трюков — распространять вредоносное ПО под видом обновления браузера . На взломанном сайте размещается плашка с утверждением, что для просмотра нужно обновить браузер. И кнопка для скачивания обновления, как на скриншоте с прошлогодней атаки ClearFake . Таким образом, жертва самостоятельно устанавливает вредоносное ПО на свой компьютер. В прошлом году злоумышленники разработали умный способ защитить вредоносный софт от уничтожения. Они разместили его в децентрализованном анонимном блокчейне . То есть интегрировали код в смарт-контракт, который навечно сохранился в открытом доступе.
https://habr.com/ru/companies/globalsign/articles/878822/
#блокчейн #обновление_браузера #BSC #Binance_Smart_Chain #Binance #BNB #WordPress #ClearFake #BscScan #EtherHiding
-
#ClearFake / #ClickFix is back infecting directly legit but vulnerable websites, delivering in the end #Lumma / #LummaStealer
-
#ClearFake / #ClickFix is back infecting directly legit but vulnerable websites, delivering in the end #Lumma / #LummaStealer
-
New Swiss centered malware campaign in German using some #ClearFake / #ClickFix tricks impersonating Ricardo, one of the biggest Swiss online second-hand marketplace:
-
New Swiss centered malware campaign in German using some #ClearFake / #ClickFix tricks impersonating Ricardo, one of the biggest Swiss online second-hand marketplace:
-
Finally we also witnessed in the wild one of those #ClearFake / #ClickFix bait delivered per email as reported by Proofpoint in June - ending with a #brutel / #Latrodectus / #BruteRatel
payload https://www.proofpoint.com/au/blog/threat-insight/clipboard-compromise-powershell-self-pwn -
Finally we also witnessed in the wild one of those #ClearFake / #ClickFix bait delivered per email as reported by Proofpoint in June - ending with a #brutel / #Latrodectus / #BruteRatel
payload https://www.proofpoint.com/au/blog/threat-insight/clipboard-compromise-powershell-self-pwn -
@monitorsg #ClearFake is back to fake browser updates. The EXE leads to a Lumma stealer that appears to use these domains.
predatowpmn[.]shop
preachstrwnwjw[.]shop
pang-scrooge-carnage[.]shoph/t @GustyDusty
-
@monitorsg #ClearFake is back to fake browser updates. The EXE leads to a Lumma stealer that appears to use these domains.
predatowpmn[.]shop
preachstrwnwjw[.]shop
pang-scrooge-carnage[.]shoph/t @GustyDusty
-
Sometimes people ask us to remove a domain from our blocklists that are part of a malicious traffic distribution system (TDS) because they "visited the url" and didn't get malware. This is like saying "I walked past the armed robber and didn't get robbed." Count yourself lucky. Say no to TDS. #dns #threatintel #cybercrime #malware #phishing #scam #infoblox #cybersecurity #infosec #tds #vextrio #socgholish #clearfake #404tds #adware
-
Sometimes people ask us to remove a domain from our blocklists that are part of a malicious traffic distribution system (TDS) because they "visited the url" and didn't get malware. This is like saying "I walked past the armed robber and didn't get robbed." Count yourself lucky. Say no to TDS. #dns #threatintel #cybercrime #malware #phishing #scam #infoblox #cybersecurity #infosec #tds #vextrio #socgholish #clearfake #404tds #adware
-
#ClearFake related contract 0xa6165aa33ac710ad5dcd4f4d6379466825476fde was updated recently and points now to daslkjfhi2[.]lol, displaying a new type of lure to visitors:
-
#ClearFake related contract 0xa6165aa33ac710ad5dcd4f4d6379466825476fde was updated recently and points now to daslkjfhi2[.]lol, displaying a new type of lure to visitors:
-
Cybersecurity Experts Warn of Rising Malware Threats from Sophisticated Social Engineering Tactics https://thecyberexpress.com/ta571-and-clearfake-campaigns/ #TheCyberExpressNews #CybersecurityNews #ClearFakecampaign #PowerShellscripts #TheCyberExpress #FirewallDaily #EtherHiding #ClearFake #TA571
-
Cybersecurity Experts Warn of Rising Malware Threats from Sophisticated Social Engineering Tactics https://thecyberexpress.com/ta571-and-clearfake-campaigns/ #TheCyberExpressNews #CybersecurityNews #ClearFakecampaign #PowerShellscripts #TheCyberExpress #FirewallDaily #EtherHiding #ClearFake #TA571
-
@cyberamateur your recently documented #clearfake pattern https://infosec.exchange/@cyberamateur/112571946191465570 seems to have changed again.
I double-checked how the new TDS b9y3b7ner2[.]xyz behaves. What I got seems to be a work-in-progress powershell script. From my partial understanding of the code so far:
- A new Binance contract is involved: 0xc12d0ca65b8bc87265b33c13bab479e5d91cc08e
- Depending on how you interact with this contract, you may get the AES encrypted value of the C2 domain, or some further payload to execute
- The key of the AES decryption is within the script itself
- The IV comes from https://rentry[.]co/t5266q3p/rawBased upon this manual analysis, the C2 appears to be hXXps://rsmbscm.wikilogistics[.]wiki/post.php
-
@cyberamateur your recently documented #clearfake pattern https://infosec.exchange/@cyberamateur/112571946191465570 seems to have changed again.
I double-checked how the new TDS b9y3b7ner2[.]xyz behaves. What I got seems to be a work-in-progress powershell script. From my partial understanding of the code so far:
- A new Binance contract is involved: 0xc12d0ca65b8bc87265b33c13bab479e5d91cc08e
- Depending on how you interact with this contract, you may get the AES encrypted value of the C2 domain, or some further payload to execute
- The key of the AES decryption is within the script itself
- The IV comes from https://rentry[.]co/t5266q3p/rawBased upon this manual analysis, the C2 appears to be hXXps://rsmbscm.wikilogistics[.]wiki/post.php
-
#ClearFake updated the TDS in contract 0x34585777843Abb908a1C5FbD6F3f620bC56874AA 3 times today:
v7yen47u2e[.]xyz
cv2b8uz46e[.]xyz
b9y3b7ner2[.]xyz (currently used)The last round of updates on this contract was on May 30th - also with 3 different domains.
-
#ClearFake has updated what it gets the end user to copy/paste into Powershell. The new code has a touch more obfuscation.
ipconfig /flushdnsis now base64'd. It uses variable names like$ERROR_FIXto appear like maybe it actually is to fix a problem.It also has a new stats feature. It will send a POST to here presumably so it knows that a user ran the initial script.
stats.drinkresources[.]rest -
Put out a fresh analysis of #ClearFake. It has some new features.
- A fake “How to fix” user experience
- Instead of a download, they convince the user to copy/paste malicious Powershell
- Very curious delayed 2-10 day go-live for infected websites
https://rmceoin.github.io/malware-analysis/2024/05/07/clearfake2.html
-
#ClearFake contract 0x34585777843Abb908a1C5FbD6F3f620bC56874AA is now updated automatically every 10 minutes, altering the used variable names. Let's see if more changes come soon... https://bscscan.com/address/0x34585777843Abb908a1C5FbD6F3f620bC56874AA
-
A bit late to the party - Randy covered it already in https://infosec.exchange/@monitorsg/112220641441840846 & https://infosec.exchange/@rmceoin/112275785843719312 - we have a new #ClearFake infection way: