{"id":10053,"date":"2026-01-22T10:04:31","date_gmt":"2026-01-22T10:04:31","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/01\/22\/new-clearfake-campaign-leveraging-proxy-execution-to-run-powershell-commands-via-trusted-window-feature\/"},"modified":"2026-01-22T10:04:31","modified_gmt":"2026-01-22T10:04:31","slug":"new-clearfake-campaign-leveraging-proxy-execution-to-run-powershell-commands-via-trusted-window-feature","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/01\/22\/new-clearfake-campaign-leveraging-proxy-execution-to-run-powershell-commands-via-trusted-window-feature\/","title":{"rendered":"New ClearFake Campaign Leveraging Proxy Execution to Run PowerShell Commands via Trusted Window Feature"},"content":{"rendered":"<p>    New ClearFake Campaign Leveraging Proxy Execution to Run PowerShell Commands via Trusted Window Feature<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>ClearFake has entered a new and more dangerous phase, turning a familiar fake CAPTCHA scam into a highly evasive malware delivery chain. <\/p>\n<p>Across hundreds of hacked websites, visitors now see what looks like a routine verification challenge, but behind the scenes the page is preparing to launch hidden code. <\/p>\n<p>Victims only need to follow simple keyboard steps, such as pressing Win + R and paste, for the attack to begin.<\/p>\n<p>This ClearFake wave matters because it blends <a href=\"https:\/\/cybersecuritynews.com\/social-engineering-tactics\/\" target=\"_blank\" rel=\"noreferrer noopener\">social engineering<\/a> with so\u2011called living off the land tactics, abusing tools already built into Windows as a trusted Windows feature instead of dropping obvious malware files. <\/p>\n<p>By shifting its infrastructure onto blockchain smart contracts and a popular content delivery network, the operation also avoids many domain and IP blocklists that defenders rely on.<\/p>\n<p>Expel analysts and researchers <a href=\"https:\/\/expel.com\/blog\/clearfake-new-lotl-techniques\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> this latest evolution while tracking ClearFake\u2019s JavaScript framework across compromised sites and examining the new loader stages. <\/p>\n<p>The team linked the campaign to a traffic distribution system that has likely pushed malware to close to 150,000 systems, based on unique IDs stored in a public smart contract visible on the BNB Smart Chain test network. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhNl8zbQeTG29S4LidjsdLoM3uMKsqCz2ZeGTKysEYKQ6FWdCpAStQZ3itFpcmgrBvVsOv_zK1twWq7QTLrP8RtqNyUcp221JxPfL8QJWeAij0bcbDpvDlQ2UX6VBmpBBaHMqc3qc9eR9K0YUBkM_0UP8GdfjHLDhQeJKr9143rEz1afKkn1dxs7huz5xc\/s16000\/A%2520graph%2520detailing%2520the%2520number%2520of%2520infections%2520per%2520day%2520since%2520the%2520smart%2520contract%2520was%2520created%2520%28Source%2520-%2520Expel%29.webp?ssl=1\" alt=\"A graph detailing the number of infections per day since the smart contract was created (Source - Expel)\"><figcaption class=\"wp-element-caption\">A graph detailing the number of infections per day since the smart contract was created (Source \u2013 Expel)<\/figcaption><\/figure>\n<\/div>\n<p>ClearFake\u2019s operators use the Ethereum\u2011style contract as a resilient command center, updating encoded <a href=\"https:\/\/cybersecuritynews.com\/new-magecart-attack-inject-malicious-javascript\/\" target=\"_blank\" rel=\"noreferrer noopener\">JavaScript<\/a> that infected pages fetch through public Web3 endpoints. <\/p>\n<h2 class=\"wp-block-heading\" id=\"h-abusing-a-trusted-windows-script-for-proxy-execution\"><strong>Abusing a Trusted Windows Script for Proxy Execution<\/strong><\/h2>\n<p>This design, combined with hosting later\u2011stage payloads on jsDelivr, a widely used CDN, means every external touchpoint in the chain sits on services defenders are reluctant to block.<\/p>\n<p>The business impact is clear: a user completing what appears to be a harmless CAPTCHA can unknowingly grant attackers code execution on a trusted corporate endpoint, with little or no trace left on disk. <\/p>\n<p>From there, follow\u2011on payloads can steal data, deploy additional malware, or provide remote access, all while hiding behind normal\u2011looking network traffic and legitimate Windows components. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhsaXukG1fphdOiXWOASuh5fhefZkXpwvU_z_UZxAHnB5rmjep42twDkCgwEhJQXtPR_5Vk0yIAy2VmigxHPZNuOh24Z0sJcYf7iAlaiChbYykeoljOouA9nbUtSyVH2V0r9UWbDmyIXZ5azpwPfEyZ90tMSDkwVn1jqbboDV3tF8V41ruFHOcNHHSpyOg\/s16000\/A%2520map%2520detailing%2520the%2520geographical%2520distribution%2520of%2520systems%2520infected%2520in%2520the%2520past%2520week%2520%28Source%2520-%2520Expel%29.webp?ssl=1\" alt=\"A map detailing the geographical distribution of systems infected in the past week (Source - Expel)\"><figcaption class=\"wp-element-caption\">A map detailing the geographical distribution of systems infected in the past week (Source \u2013 Expel)<\/figcaption><\/figure>\n<\/div>\n<p>At the heart of the new technique is SyncAppvPublishingServer.vbs, a legitimate script in the Windows System32 folder that ships as part of App\u2011V management. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgqFme47S2HqcMiSvDk7d1R4hTcKISOwAmQy3Db1EzE9kI_mUiNFGAoxFa3Cwe3Yy-hCx42lk_1lt8dtprQ-LhWDgOKWIcAIkmxQHimVaeHAXO9w7uzsdXZAaxCKzI9GVXQ26I6YF7yAo1mTvFs0e_KW2Ic7fGce0dCCTynN3nefhJGyQ7CV8KhH9vSTi8\/s16000\/After%2520the%2520users%2520click%2520%27I%25E2%2580%2599m%2520not%2520a%2520robot%27%2520they%25E2%2580%2599re%2520presented%2520with%2520the%2520social%2520engineering%2520lure%2520%28Source%2520-%2520Expel%29.webp?ssl=1\" alt=\"After the users click 'I\u2019m not a robot' they\u2019re presented with the social engineering lure (Source - Expel)\"><figcaption class=\"wp-element-caption\">After the users click \u2018I\u2019m not a robot\u2019 they\u2019re presented with the social engineering lure (Source \u2013 Expel)<\/figcaption><\/figure>\n<\/div>\n<p>ClearFake\u2019s <a href=\"https:\/\/cybersecuritynews.com\/fake-captcha-delivers-eddiestealer\/\" target=\"_blank\" rel=\"noreferrer noopener\">fake CAPTCHA<\/a> instructs users to open the Run dialog, where the clipboard holds a carefully crafted command that passes a malicious argument into this script.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/new-clearfake-campaign-leveraging-proxy-execution\/\">New ClearFake Campaign Leveraging Proxy Execution to Run PowerShell Commands via Trusted Window Feature<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/new-clearfake-campaign-leveraging-proxy-execution\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New ClearFake Campaign Leveraging Proxy Execution to Run PowerShell Commands via Trusted Window Feature ClearFake has entered a new and more dangerous phase, turning a familiar fake CAPTCHA scam into a highly evasive malware delivery chain. Across hundreds of hacked websites, visitors now see what looks like a routine verification challenge, but behind the scenes [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-10053","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10053"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=10053"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10053\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=10053"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=10053"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=10053"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}