Introduction: ClearFake Malware — Why It Matters
ClearFake Malware has reportedly evolved into a more complex multi-stage attack chain that combines fake CAPTCHA pages, social engineering, cryptocurrency theft and endpoint security evasion. The campaign can reportedly trick victims into executing malicious commands before deploying additional payloads.
According to the reported Cisco Talos investigation, the activity was identified after unusual remote library execution was observed at a Ukrainian government organization in April 2026. The investigation also tracked a remote-loader branch as UAT-10820.
The campaign demonstrates how ClickFix-style attacks can move beyond simple malware delivery. Instead, attackers reportedly combine WebDAV, blockchain-based infrastructure, vulnerable signed drivers and persistence mechanisms to make detection and disruption more difficult.
What Caused the Incident?
The ClearFake Malware attack begins with compromised websites displaying fake Google CAPTCHA prompts. Rather than simply asking visitors to verify that they are human, the fraudulent pages reportedly instruct users to perform actions involving the Windows Run dialog.
The social-engineering process can lead victims to:
- Open the Windows Run dialog.
- Paste an attacker-provided command.
- Execute the command manually.
- Trigger additional malicious downloads and execution.
This approach abuses user interaction to bypass some traditional security controls. Because the victim initiates the command, the activity can appear less suspicious than a conventional drive-by malware infection.
ClearFake Malware: Full Technical Breakdown
Timeline of Events
The ClearFake Malware attack reportedly follows a multi-stage sequence:
- A compromised website presents a fake CAPTCHA or ClickFix prompt.
- The victim is persuaded to execute a command through Windows Run.
- Blockchain-hosted instructions help provide changing infrastructure information.
- WebDAV is used to retrieve disguised malicious libraries.
- One branch deploys ZigCryptoStealer for cryptocurrency-related theft.
- Another branch reportedly deploys a vulnerable signed driver to terminate security processes.
- A separate branch installs a remote-access client and establishes persistence through a scheduled task.
What Systems Are Affected?
The reported attack chain can target Windows systems and potentially affect:
- Cryptocurrency wallets and clipboard activity.
- Endpoint Detection and Response (EDR) processes.
- Windows systems using targeted security products.
- Systems receiving malicious libraries through WebDAV.
- Systems where unauthorized remote-access software can establish persistence.
One major concern is the reported use of DCRCVDrv.sys, a legitimate but vulnerable signed Windows driver. The driver is abused through a Bring Your Own Vulnerable Driver (BYOVD) technique.
The malware reportedly provides process IDs associated with EDR products to the vulnerable driver, allowing those security processes to be forcibly terminated.
Potential Risks & Impact
Financial Risk
ZigCryptoStealer reportedly monitors cryptocurrency wallet addresses copied to the clipboard. It can replace a legitimate wallet address with an attacker-controlled address, potentially redirecting cryptocurrency payments without the victim immediately noticing.
Business and Security Risk
Terminating EDR processes can weaken endpoint visibility and allow additional malicious activity to continue with reduced security monitoring. The separate remote-access branch also reportedly provides attackers with unauthorized access and persistence.
Operational Risk
The use of blockchain infrastructure and changing command information can make conventional blocking strategies less effective. Organizations may therefore need to investigate behavior across endpoints, networks and user activity rather than relying only on static indicators.
Official Response / Statement
The reported technical findings come from Cisco Talos’ investigation into the ClearFake WebDAV infection chain, which identified and analyzed the activity. The investigation links the remote-loader branch to the tracking designation UAT-10820.
No additional company or government statement was provided in the supplied information. Organizations should therefore treat the technical findings as reported security research and monitor for additional indicators as the investigation develops.
Industry Context: Why This Type of Attack Is Increasing
The ClearFake Malware campaign’s reported evolution reflects a broader shift toward attacks that combine social engineering with multiple technical evasion techniques.
ClickFix campaigns are particularly effective because they persuade users to perform actions that security products might otherwise block automatically. At the same time, BYOVD techniques allow attackers to abuse trusted but vulnerable drivers to interfere with security software.
The campaign’s use of EtherHiding is another notable development. By storing changing command-and-control information through blockchain contracts, attackers can make parts of their infrastructure harder to disrupt.
Organizations can follow broader cyber incident updates to track similar attack patterns.
How to Protect Yourself / Your Organization
- Train users against fake CAPTCHA attacks: Employees should never execute commands simply because a website instructs them to do so.
- Monitor Windows Run activity: Investigate suspicious commands launched through
explorer.exe, Run dialogs or unusual script interpreters. - Inspect WebDAV traffic: Unexpected WebDAV connections and remote library retrieval should receive additional scrutiny.
- Block vulnerable drivers: Maintain driver blocklists and use security controls capable of detecting known vulnerable signed drivers. Organizations can also review Microsoft’s recommended driver block rules for additional protection guidance.
- Monitor EDR processes: Investigate unexpected termination or repeated failures of security agents.
- Audit scheduled tasks: Look for newly created tasks that launch unfamiliar executables or remote-access software.
- Protect cryptocurrency transactions: Verify wallet addresses independently instead of relying solely on copied clipboard values.
- Strengthen endpoint visibility: Ensure security tools generate alerts when drivers, rundll32 activity or remote-access clients appear unexpectedly.
Additional security guidance is available through CyberNexora’s Learn & Protect resources.
Indicators of Compromise (IoCs)
Reported indicators associated with the activity include:
- DCRCVDrv.sys — vulnerable signed Windows driver abused for defense evasion.
- ZigCryptoStealer — cryptocurrency-focused malware branch.
- Malicious WebDAV-hosted libraries.
- Blockchain contracts used for changing infrastructure information.
- Malicious domains and command-and-control infrastructure.
- Unexpected
rundll32execution. - Unauthorized remote-access clients.
- Newly created scheduled tasks.
The reported investigation also provides hashes, domains, blockchain contracts, file names and additional infrastructure indicators for defenders to use in detection.
Key Takeaways
- ClearFake has reportedly expanded beyond fake CAPTCHA delivery into a multi-stage malware operation.
- ZigCryptoStealer can reportedly replace cryptocurrency wallet addresses copied to the clipboard.
- The campaign abuses a vulnerable signed driver to terminate endpoint security processes.
- EtherHiding and WebDAV add additional layers of infrastructure and delivery complexity.
- Organizations should prioritize user awareness, driver monitoring and endpoint behavioral detection.
Conclusion: ClearFake Malware and What Happens Next
ClearFake Malware highlights how attackers can combine social engineering, cryptocurrency theft and defense evasion into one infection chain. The reported abuse of DCRCVDrv.sys is particularly significant because disabling security processes can provide malware with more freedom to operate after initial execution.
Security teams should watch for fake CAPTCHA activity, suspicious WebDAV connections, unusual rundll32 execution, vulnerable drivers and unexpected scheduled tasks. Organizations can also review CyberNexora’s latest cybersecurity incident coverage as similar techniques continue to emerge.
Frequently Asked Questions (FAQs)
ClearFake Malware refers to the reported evolution of the ClearFake campaign into a multi-stage attack involving fake CAPTCHA pages, cryptocurrency theft and endpoint security evasion. The campaign reportedly uses several techniques to deliver and maintain malicious activity.
ZigCryptoStealer is the reported cryptocurrency-stealing component of one ClearFake infection branch. It can monitor copied cryptocurrency wallet addresses and potentially replace them with attacker-controlled addresses.
The campaign reportedly uses the BYOVD technique by deploying the vulnerable signed driver DCRCVDrv.sys. The driver can reportedly receive EDR-related process IDs and terminate those security processes.
ClickFix is a social-engineering method that tricks users into performing actions such as opening Windows Run and executing attacker-provided commands. In this campaign, fake CAPTCHA prompts reportedly help initiate that process.
ClearFake reportedly uses EtherHiding to store changing command-and-control information through blockchain contracts. This can make the underlying infrastructure more difficult for defenders to disrupt.
Organizations should train users to recognize fake CAPTCHA and ClickFix prompts, monitor WebDAV activity, investigate suspicious rundll32 execution, block vulnerable drivers and audit scheduled tasks. Endpoint security teams should also investigate unexpected termination of EDR processes.
