Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
ClearFake Crypto Stealer Exploits Vulnerabilities

ClearFake Crypto Stealer Exploits Vulnerabilities

Posted on September 9, 2026 By CWS

ClearFake has initiated a sophisticated scheme that not only targets cryptocurrency and credentials but also disables endpoint protection systems. By compromising websites, it converts them into platforms for attack, tricking users into executing what seems like a harmless command.

Mechanism of the Attack

The attack begins with the injection of browser code and blockchain-hosted instructions, presented as a Google CAPTCHA through a ClickFix prompt. When users comply, a remote loader retrieves a concealed library via WebDAV.

Cisco Talos researchers detected this activity after observing remote library execution at a Ukrainian government office in April 2026. This was found to be part of a larger theft operation, not an isolated incident.

Impact of the Crypto Stealer

The consequences of these attacks are significant. The crypto stealer modifies copied wallet addresses, redirecting funds to attackers. It also allows remote access, offering a pathway from a deceptive page to persistent control and monetary theft.

Cisco Talos reported that this activity, connected to a remote-loader branch called UAT-10820, represents a serious threat. The crypto-stealer branch initially receives instructions to download an archive, where a signed Chrome component is manipulated to load a malicious library using DLL side-loading techniques.

Technical Details and Defense Measures

This attack employs a vulnerable Windows driver to disable EDR tools, a tactic known as BYOVD (bring-your-own-vulnerable-driver). This approach undermines device protection by stopping key processes.

The malware, ZigCryptoStealer, monitors clipboard activities for cryptocurrency addresses, replacing them with addresses controlled by attackers. It uses a blockchain contract to dynamically alter its command infrastructure, enabling rapid campaign changes while maintaining malicious operations away from primary delivery systems.

The attack starts by compromising a website and injecting JavaScript through a rogue Cloudflare Worker. This script checks a visitor’s environment, retrieves additional code from BNB Smart Chain, and presents a verification prompt.

From Deception to Control

The prompt instructs users to open the Run dialog and execute a command, accessing a remote WebDAV path to execute a library export. This method bypasses the need for a browser exploit, aligning with the ClickFix WebDAV delivery tactic.

A parallel branch follows a similar WebDAV pattern but culminates in a PowerShell script installation, setting up an unauthorized remote-access client. This grants attackers the ability to collect sensitive information and execute commands, raising the stakes for potential victims.

Organizations should educate their staff that legitimate CAPTCHA checks do not require executing commands via Run, Terminal, PowerShell, or Command Prompt. Security teams should scrutinize unusual WebDAV traffic, unexpected driver services, and new scheduled tasks, while employing driver blocklists and protections against vulnerable drivers.

Cyber Security News Tags:Blockchain, BYOVD attack, CAPTCHA scam, ClearFake, crypto stealer, cyber attack, Cybersecurity, DLL side-loading, EDR tools, endpoint protection, Malware, Phishing, remote access, vulnerable driver, WebDAV

Post navigation

Previous Post: Google Releases Patches for 180 Android Vulnerabilities
Next Post: Microsoft Defender Vulnerability Bypass Exposed

Related Posts

Canon Allegedly Breached by Clop Ransomware via Oracle E-Business Suite 0-Day Hack Canon Allegedly Breached by Clop Ransomware via Oracle E-Business Suite 0-Day Hack Cyber Security News
Ransomware Gangs Actively Expanding to Attack VMware and Linux Systems Ransomware Gangs Actively Expanding to Attack VMware and Linux Systems Cyber Security News
SharePoint 0-day Vulnerability Exploited in Wild by All Sorts of Hacker Groups SharePoint 0-day Vulnerability Exploited in Wild by All Sorts of Hacker Groups Cyber Security News
Lenovo AI Chatbot Vulnerability Let Attackers Run Remote Scripts on Corporate Machines Lenovo AI Chatbot Vulnerability Let Attackers Run Remote Scripts on Corporate Machines Cyber Security News
Phishing Scam Targets Job Seekers via Fake Recruiter Emails Phishing Scam Targets Job Seekers via Fake Recruiter Emails Cyber Security News
Dell Patches Critical PowerProtect Flaws Allowing Remote Access Dell Patches Critical PowerProtect Flaws Allowing Remote Access Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Exploit Job Offers on LinkedIn to Spread Malware
  • HelmGuard Secures $7.3M to Enhance AI Governance and Security
  • Microsoft Defender Vulnerability Bypass Exposed
  • ClearFake Crypto Stealer Exploits Vulnerabilities
  • Google Releases Patches for 180 Android Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Exploit Job Offers on LinkedIn to Spread Malware
  • HelmGuard Secures $7.3M to Enhance AI Governance and Security
  • Microsoft Defender Vulnerability Bypass Exposed
  • ClearFake Crypto Stealer Exploits Vulnerabilities
  • Google Releases Patches for 180 Android Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark