EXECUTIVE SUMMARY:
ClearFake is a malicious JavaScript framework actively targeting compromised websites to deliver malware through drive-by downloads. Initially designed to trick users into downloading counterfeit browser updates, the framework has evolved to use more sophisticated social engineering tactics. This includes the deceptive use of fake error messages and CAPTCHA challenges, such as fake reCAPTCHA or Cloudflare Turnstile verifications, to persuade users into executing harmful PowerShell commands. This malware has been found to exploit the Binance Smart Chain and blockchain technology to deliver its malicious payloads, making it harder to detect and remove.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
ClearFake is a malicious JavaScript framework actively targeting compromised websites to deliver malware through drive-by downloads. Initially designed to trick users into downloading counterfeit browser updates, the framework has evolved to use more sophisticated social engineering tactics. This includes the deceptive use of fake error messages and CAPTCHA challenges, such as fake reCAPTCHA or Cloudflare Turnstile verifications, to persuade users into executing harmful PowerShell commands. This malware has been found to exploit the Binance Smart Chain and blockchain technology to deliver its malicious payloads, making it harder to detect and remove.[emaillocker id="1283"]
ClearFake begins by injecting a brief JavaScript code into compromised websites, usually running on WordPress. The malicious script interacts with the Binance Smart Chain via smart contract interfaces to fetch additional JavaScript payloads. The code retrieves encrypted data stored in smart contracts and uses AES-GCM decryption to deliver the payload. This payload is embedded into an iframe, displayed as a fake browser update or CAPTCHA challenge. Once users attempt to resolve these challenges, they are misled into executing a PowerShell script that installs malware on their systems. The malware, often disguised as video files, executes a series of obfuscated commands that ultimately install infostealers such as Lumma or Vidar Stealer. By leveraging blockchain for hosting its code and lures, ClearFake makes its malicious content persist even if the website is cleaned, further complicating mitigation efforts.
ClearFake is a persistent and evolving threat that continues to exploit blockchain technology for its malicious operations. Its use of smart contracts for distributing malicious payloads and executing harmful commands makes it a particularly challenging threat to mitigate. The framework’s ability to embed its code in widely visited websites significantly amplifies its reach, affecting many users globally. It must remain vigilant against this increasingly malware, employ robust endpoint protection, and monitor network traffic for unusual PowerShell activity to reduce the risk of infection.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1189 | Drive-by Compromise |
| Execution | T1059 | Command and Scripting Interpreter |
| Persistence | T1547 | Boot or Logon Autostart Execution |
| Defense Evasion | T1027 | Obfuscated Files or Information |
| Discovery | T1082 | System Information Discovery |
| T1012 | Query Registry | |
| Collection | T1056 | Input Capture |
| Command and Control | T1071 | Application Layer Protocol |
| Exfiltration | T1567 | Exfiltration Over Web Service |
| Impact | T1485 | Data Destruction |
REFERENCES:
The following reports contain further technical details:
[/emaillocker]