ClearFake Infects 9,300 Sites, Uses Fake reCAPTCHA and Turnstile to Spread Info-Stealers
The threat actors behind the ClearFake campaign are tricking users into downloading malware like Lumma Stealer and Vidar Stealer by utilizing phony reCAPTCHA or Cloudflare Turnstile verifications as baits.
First identified in July 2023, the threat activity cluster known as ClearFake uses hacked WordPress to distribute malware by using phony online browser update baits.
The campaign also has a reputation for using Binance's Smart Chain (BSC) contracts to make the assault chain more robust by using another method called EtherHiding to retrieve the next-stage payload. These infection chains ultimately aim to spread malware that steals information and can infect Windows and macOS systems read more about ClearFake Infects 9300 Sites Uses Fake reCAPTCHA and Turnstile to Spread Info-Steale...


