ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools

ClearFake has expanded a fake CAPTCHA scam into a chain that steals cryptocurrency and credentials while disabling endpoint protection. It turns compromised websites into launchpads, relying on visitors to run a command that appears routine.

ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools

Share this story

Send the public story page.

Useful takeaways from this story.

ClearFake has expanded a fake CAPTCHA scam into a chain that steals cryptocurrency and credentials while disabling endpoint protection.

It turns compromised websites into launchpads, relying on visitors to run a command that appears routine.

The operation begins with injected browser code, blockchain-hosted instructions, and a ClickFix prompt styled as a Google CAPTCHA.

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

ClearFake has expanded a fake CAPTCHA scam into a chain that steals cryptocurrency and credentials while disabling endpoint protection. It turns compromised websites into launchpads, relying on visitors to run a command that appears routine. The operation begins with injected browser code, blockchain-hosted instructions, and a ClickFix prompt styled as a Google CAPTCHA.

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app