Skip to content
Malware family

ClearFake

ClearFake is a cybercriminal web-inject activity cluster first identified in 2023 that compromises legitimate websites and injects malicious HTML and JavaScript to deliver malware through fake browser update, fake CAPTCHA, and related social-engineering lures.

Profile source: Mallory opens in a new tab

ClearFake

Family profile

ClearFake is a cybercriminal web-inject activity cluster first identified in 2023 that compromises legitimate websites and injects malicious HTML and JavaScript to deliver malware through fake browser update, fake CAPTCHA, and related social-engineering lures. It is widely associated with drive-by delivery chains in which visitors to compromised sites are profiled and then presented with deceptive prompts that persuade them to execute attacker-supplied commands themselves, most notably through the ClickFix or paste-and-run technique. ClearFake has also been linked to EtherHiding, using blockchain-hosted content to conceal or stage malicious scripts.

ClearFake primarily operates by abusing compromised web infrastructure rather than exploiting endpoint vulnerabilities. Its infection chains commonly rely on JavaScript-based web injects, clipboard manipulation, fake certificate or browser-fix prompts, and command execution via Windows utilities such as PowerShell, mshta, and msbuild. Reported tradecraft includes multi-stage in-memory loaders, sandbox-evasion checks, AMSI and ETW bypass attempts, use of traffic distribution systems for filtering and redirection, and delivery of additional payloads through staged scripts and archives. ClearFake has been described as an early adopter and prominent user of ClickFix-style user-execution tradecraft.

Payloads delivered through ClearFake infrastructure have included Lumma Stealer, Amatera Stealer, ACR Stealer, NetSupport RAT, Rhadamanthys, Vidar, and other commodity malware. Reporting has also linked ClearFake delivery chains to loaders such as DOILoader/HijackLoader and to follow-on malware including Amadey and cryptocurrency-mining components in some campaigns. By 2025 and 2026, ClearFake was assessed as one of the more prevalent fake-update and web-inject clusters in enterprise telemetry.

ClearFake is tracked by some researchers as UNC5142 in connection with EtherHiding-related activity. It is generally treated as a financially motivated threat cluster rather than a nation-state actor. No single definitive operator attribution is broadly established, and it is typically discussed as an activity cluster rather than a formally identified group with confirmed membership or command structure.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 21, 2026
Last activity
Jul 21, 2026
Feed role
C2
Host form
1 IP / 0 hostnames

Leading locations

  • MD1

Leading providers

  • ALEXHOST SRL1

Infrastructure traits

  • Hosting 1

MITRE ATT&CK

ClearFake in ATT&CK

46 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.