ClearFake
- First seen
- 2020-05-01 00:00:00
- Malware type
- downloader, exploit-kit
- Family
- Malware family
- Last IoC activity
- 2026-07-22 04:25:03
- Profile updated
- 2026-07-07 14:32:45
Targeted industries: retail-and-hospitality technology-and-telecommunications
Context
ClearFake is a malicious JavaScript framework deployed on compromised websites to deliver further malware using the drive-by download technique. The malware leverages social engineering to trick the user into running a fake web browser update.
Used by threat actors
- PowerShell User Execution Social Engineering Campaign (TA571, ClearFake, ClickFix) (campaign)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Js.Clearfake (report)
- blog.sekoia.io — Clearfake A Newcomer To The Fake Updates Threats Landscape (report)
- kroll.com — Clearfake Update Tricks Victim Executing Malicious Powershell Code (report)
- blog.morphisec.com — Coinlurker The Stealer Powering The Next Generation Of Fake Updates (report)
- rmceoin.github.io — Clearfake (report)