Threat Advisory

ClearFake Malware Uses Fake reCAPTCHA to Deliver Malicious PowerShell Code

Threat: Malware
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

ClearFake is a malicious JavaScript framework actively targeting compromised websites to deliver malware through drive-by downloads. Initially designed to trick users into downloading counterfeit browser updates, the framework has evolved to use more sophisticated social engineering tactics. This includes the deceptive use of fake error messages and CAPTCHA challenges, such as fake reCAPTCHA or Cloudflare Turnstile verifications, to persuade users into executing harmful PowerShell commands. This malware has been found to exploit the Binance Smart Chain and blockchain technology to deliver its malicious payloads, making it harder to detect and remove.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

ClearFake is a malicious JavaScript framework actively targeting compromised websites to deliver malware through drive-by downloads. Initially designed to trick users into downloading counterfeit browser updates, the framework has evolved to use more sophisticated social engineering tactics. This includes the deceptive use of fake error messages and CAPTCHA challenges, such as fake reCAPTCHA or Cloudflare Turnstile verifications, to persuade users into executing harmful PowerShell commands. This malware has been found to exploit the Binance Smart Chain and blockchain technology to deliver its malicious payloads, making it harder to detect and remove.[emaillocker id="1283"]

ClearFake begins by injecting a brief JavaScript code into compromised websites, usually running on WordPress. The malicious script interacts with the Binance Smart Chain via smart contract interfaces to fetch additional JavaScript payloads. The code retrieves encrypted data stored in smart contracts and uses AES-GCM decryption to deliver the payload. This payload is embedded into an iframe, displayed as a fake browser update or CAPTCHA challenge. Once users attempt to resolve these challenges, they are misled into executing a PowerShell script that installs malware on their systems. The malware, often disguised as video files, executes a series of obfuscated commands that ultimately install infostealers such as Lumma or Vidar Stealer. By leveraging blockchain for hosting its code and lures, ClearFake makes its malicious content persist even if the website is cleaned, further complicating mitigation efforts.

ClearFake is a persistent and evolving threat that continues to exploit blockchain technology for its malicious operations. Its use of smart contracts for distributing malicious payloads and executing harmful commands makes it a particularly challenging threat to mitigate. The framework’s ability to embed its code in widely visited websites significantly amplifies its reach, affecting many users globally. It must remain vigilant against this increasingly malware, employ robust endpoint protection, and monitor network traffic for unusual PowerShell activity to reduce the risk of infection.

 

THREAT PROFILE:

Tactic Technique Id Technique
Initial Access T1189 Drive-by Compromise
Execution T1059 Command and Scripting Interpreter
Persistence T1547 Boot or Logon Autostart Execution
Defense Evasion T1027 Obfuscated Files or Information
Discovery T1082 System Information Discovery
T1012 Query Registry
Collection T1056 Input Capture
Command and Control T1071 Application Layer Protocol
Exfiltration T1567 Exfiltration Over Web Service
Impact T1485 Data Destruction

 

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu