Advertise
CoinTrust
BTC
ETH
BCH
SOL
DOGE
SHIB
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
No Result
View All Result

Home » ClearFake Malware Exploits Web3 for Sophisticated Cyber Attacks

ClearFake Malware Exploits Web3 for Sophisticated Cyber Attacks

Web3 Abused to Deliver Malicious Payloads

Kelly Cromley by Kelly Cromley
Mar 20, 2025
in Market News, News
Reading Time: 3 mins read
0
Malware

Cybersecurity analysts have raised concerns over the latest ClearFake malware variant, which leverages Web3 capabilities to execute malicious operations using blockchain technology. Reports indicate that the malware utilizes smart contracts on the blockchain to store and deliver malicious scripts, resources, and payloads, complicating detection and mitigation efforts.

Tactics and Techniques Behind ClearFake

According to cybersecurity platform Sekoia.io, ClearFake primarily targets compromised WordPress websites to propagate its malware. The malware campaign employs a social engineering technique known as ClickFix, tricking users into executing malicious PowerShell scripts on their systems. Victims are typically shown a deceptive error message urging them to manually copy and run the malicious code via their Windows terminal.

Initially detected in July 2023, ClearFake previously lured users through fake web browser update pages. However, reports suggest that by May 2024, the threat actors shifted to using ClickFix. By mid-2024, approximately 200,000 unique users had accessed ClearFake-compromised websites, indicating the scale of the threat.

Use of Blockchain for Malware Distribution

The latest version of ClearFake, traced back to December 2024, has introduced new phishing tactics, including fake CAPTCHA pages and the integration of JavaScript frameworks. In a more alarming development, cybercriminals have been utilizing Binance Smart Chain (BSC) smart contracts to deliver various malware components, including ClickFix payloads.

Smart contracts, generally employed to facilitate blockchain transactions, are exploited in this case to store malicious files. Attackers embed files within the “Input Data” field of the smart contracts, which are then retrieved during the attack. This method ensures persistent storage of malicious payloads, immune to traditional takedown efforts.

When a user visits a compromised site, JavaScript embedded in the page loads specific Application Binary Interfaces (ABIs) to interact with Ethereum-based smart contracts. These ABIs contain functions and data structures that allow the malware to retrieve encrypted files, including malicious HTML and JavaScript payloads.

ClearFake’s malicious files are often hosted on Cloudflare Pages. The malware retrieves decryption keys from multiple Ethereum wallets, ensuring redundancy and making its takedown more challenging.

EtherHiding: Evasion Through Blockchain

The technique used by ClearFake to obscure malicious activities is referred to as EtherHiding. This approach allows cybercriminals to store malicious code on blockchain platforms like Ethereum and BSC. ClearFake previously applied EtherHiding on a smaller scale in October 2023, fetching a single malicious JavaScript file from its Ethereum address. The technique effectively bypasses traditional security measures, as blockchain-stored data remains immutable.

The continued use of EtherHiding by ClearFake highlights its adaptability and resilience. Security experts warn that this method makes it harder for cybersecurity teams to identify and eliminate the malware.

Social Engineering and Malware Deployment

The updated phishing tactics used by ClearFake involve fake CAPTCHA pages resembling Cloudflare Turnstile or Google reCAPTCHA. Victims attempting to pass these CAPTCHAs are shown deceptive error messages suggesting abnormal web traffic. They are then prompted to run PowerShell commands under the pretense of resolving the issue.

Upon execution, the malicious commands download and run additional payloads, including Emmental Loader and Lumma Stealer. In some cases, the Vidar Stealer malware is deployed using basic PowerShell loaders. These payloads are designed to extract sensitive information, including login credentials and financial data.

Scale of Impact and Detection Efforts

By tracking wallet addresses associated with the ClearFake campaign, Sekoia.io analysts conducted scans using Censys and identified over 9,300 compromised websites as of February 24, 2025. This substantial network of affected sites underlines the extensive reach of the malware campaign.

Cybersecurity experts have noted the advancements in ClearFake’s use of blockchain for malicious purposes. These recent developments, including the expanded implementation of EtherHiding, were previously documented by independent researcher Marek Szustak in January 2025.

Security professionals continue to recommend vigilance against such attacks, advising users to avoid executing unfamiliar commands and implement robust cybersecurity measures to mitigate risks.

Previous Post

AI-Powered Analytics: RateXAI Labs Launches Meta Scoring Engine

Next Post

AB DAO Partners with Alpha Technology Group to Advance AI and Blockchain Integration

Related Posts

Venezuela

Venezuelans Turn to Stablecoins as Economic Lifeline

by Kelly Cromley
Dec 14, 2025
0

As Venezuela continues to face prolonged economic instability and persistent volatility, citizens are increasingly seeking alternatives to traditional financial systems....

everclear partners with router protocol

Everclear and Router Protocol Tackle Cross-Chain Liquidity Gaps

by Kelly Cromley
Dec 14, 2025
0

Everclear, a decentralized protocol focused on cross-chain clearing and settlement, has entered into a strategic partnership with Router Protocol, a...

Ethereum

Ethereum Developers Propose ERC-8092 to Simplify Multi-Chain Wallet Identity

by Kelly Cromley
Dec 14, 2025
0

Ethereum developers have put forward a new draft proposal known as ERC-8092, designed to tackle a growing challenge in the...

state street

State Street Selects Solana for Institutional Asset Tokenization

by Kelly Cromley
Dec 14, 2025
0

Global asset management firm State Street has moved forward with adopting Solana as the core infrastructure for its asset tokenization...

nomis

Nomis and MindKit Join Forces to Power AI-Driven Web3 Reputation

by Kelly Cromley
Dec 14, 2025
0

Nomis, an established on-chain reputation protocol, has entered into a strategic partnership with MindKit, a decentralized entity specializing in artificial...

ripple decentralized ledger

AMINA Bank Integrates Ripple to Modernize Cross-Border Payments

by Kelly Cromley
Dec 13, 2025
0

AMINA Bank, a Switzerland-based financial institution regulated by FINMA, has implemented Ripple Payments to improve how transactions flow between blockchain...

Next Post
ab dao partners with alpha technology group to advance ai and blockchain integration

AB DAO Partners with Alpha Technology Group to Advance AI and Blockchain Integration

  • Collé Ai

    Collé: Pioneering AI Web3 Platform Receives Investment Boost from BlackRock

    by Kelly Cromley
    May 13, 2024
  • Router Protocol and OpenWorldSwap Partnership to Revolutionize DEX Market

    by Kelly Cromley
    Aug 6, 2024
  • Hyper Foundation Launched to Boost Hyperliquid Blockchain Development

    by Kelly Cromley
    Oct 15, 2024
  • SmarTrust Brings Blockchain-Powered Escrow to Freelancers

    by Kelly Cromley
    May 1, 2025
  • Blockchain Based Sports Platform SportsMint Unveiled

    by Kelly Cromley
    Apr 30, 2024

Recent News

Venezuela
Market News

Venezuelans Turn to Stablecoins as Economic Lifeline

by Kelly Cromley
Dec 14, 2025
everclear partners with router protocol
Market News

Everclear and Router Protocol Tackle Cross-Chain Liquidity Gaps

by Kelly Cromley
Dec 14, 2025
Ethereum
Ethereum News

Ethereum Developers Propose ERC-8092 to Simplify Multi-Chain Wallet Identity

by Kelly Cromley
Dec 14, 2025
state street
Market News

State Street Selects Solana for Institutional Asset Tokenization

by Kelly Cromley
Dec 14, 2025
nomis
Market News

Nomis and MindKit Join Forces to Power AI-Driven Web3 Reputation

by Kelly Cromley
Dec 14, 2025

Categories

  • Altcoin News
  • Analysis News
  • Binance Coin News
  • Bitcoin News
  • Blog
  • Cardano News
  • Ethereum News
  • ICO News
  • Legislation News
  • Market Forecasts
  • Market News
  • News
  • Ripple News
  • Solana News
  • Tether News
  • XRP
Trustpilot

Cointrust

  • About Us
  • Contact Us
  • Correction Request
  • Our Team

Legal

  • Disclaimer
  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy

Popular

  • ICO Listings
  • Knowledge Base
  • All about Mining
  • Cryptocurrency Exchanges
  • How and Where to buy Cryptocurrency

Sitemap

  • News section
  • Sitemap
  • XML Sitemap

© 2024 CoinTrust.com.

CoinTrustCoinTrust

* DISCLAIMER: All information provided in CoinTrust is merely for informational purposes, we are not an investment advisor and not affiliated with any companies or ICO/Cryptocurrency Projects. To use this website you must accept our cookie policy, Disclaimer and Privacy Policies.

No Result
View All Result
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos

© 2024 CoinTrust.com.

We use cookies to ensure that we give you the best experience on our website.
If you continue to use this site you agree to allow us to use cookies, in accordance with our Cookie Policy.