The ClearFake crypto stealer campaign is turning compromised websites into launchpads for credential and cryptocurrency theft. Cisco Talos says the infection chain can also disable endpoint detection and response (EDR) tools, allowing malicious payloads to operate with less chance of being stopped.
The activity combines a fake CAPTCHA, user-executed commands, WebDAV delivery, DLL side-loading and abuse of a vulnerable driver. Talos identified the campaign after investigating unusual remote library execution at a Ukrainian government organisation in April 2026.
ClearFake crypto stealer campaign discovered
ClearFake begins on legitimate websites that attackers have compromised by injecting malicious browser code. Visitors are presented with a ClickFix prompt designed to resemble a Google CAPTCHA, creating the impression that they must complete a routine verification step before continuing.
Unlike a fully automatic browser exploit, the chain depends on the visitor following instructions and running a command. This social engineering step gives the attacker a way to move from browser content into the Windows environment without relying solely on a software vulnerability in the browser.
The injected code also uses blockchain-hosted instructions. This provides the operation with an external mechanism for directing infected systems towards its next-stage infrastructure and payloads. Once the command is executed, a remote loader retrieves and runs a disguised library through WebDAV.
WebDAV is a protocol for accessing and managing files on remote web servers. In this campaign, it lets the attackers present remote content in a way that supports the execution of the next malicious stage. The ClearFake crypto stealer chain therefore blends web-based deception with trusted Windows functionality.
How the WebDAV infection chain operates
Cisco Talos detected the activity after observing unusual remote library execution at a Ukrainian government organisation in April 2026. Its researchers linked the remote-loader branch to an activity cluster tracked as UAT-10820.
Talos assessed that the incident was part of a broader theft operation rather than a campaign specifically targeting that organisation. The people most directly at risk are visitors to compromised websites who encounter the fake CAPTCHA and carry out its instructions.
The reported infection sequence includes these stages:
- A legitimate website is compromised and supplied with injected browser code.
- The visitor receives a ClickFix prompt styled as a Google CAPTCHA.
- The prompt convinces the visitor to run a command on the device.
- A remote loader obtains and executes a disguised library through WebDAV.
- Further payloads are installed according to the branch selected by the attackers.
- The resulting malware can steal data, manipulate wallet addresses or provide remote access.
This design makes the initial interaction appear familiar while moving several important stages away from the webpage itself. Security teams may therefore see remote library execution, archive retrieval or unexpected signed application activity after the original browser event.
DLL side-loading installs the crypto stealer
In the cryptocurrency theft branch, the first payload receives instructions to download an archive. That archive contains a legitimate, digitally signed Chrome component alongside a malicious library placed where the trusted component will load it.
This method is known as DLL side-loading. A legitimate executable searches for a required dynamic-link library, but loads the attacker’s file because it has been placed in an expected location. The trusted component then becomes the mechanism through which malicious code runs.
For the ClearFake crypto stealer, this approach helps the payload blend into activity involving a signed application component. A signed file is not necessarily malicious, but its presence can make the surrounding execution chain appear less suspicious if monitoring focuses only on whether an executable has a valid signature.
Once active, the crypto stealer can change cryptocurrency wallet addresses copied by the user. A victim intending to make a payment may paste an attacker-controlled address instead of the original destination, creating a direct route to financial theft.
Vulnerable driver abuse disables EDR
The campaign also uses a vulnerable driver to neutralise EDR security tools. This technique can give malicious code access to privileged capabilities exposed by a legitimate but flawed driver, allowing the attacker to interfere with security processes from a more trusted position in the operating system.
Disabling endpoint protection changes the impact of the incident. The ClearFake crypto stealer is not limited to collecting information exposed through a browser session. It can gain time to run additional payloads, maintain access and carry out theft while endpoint controls are impaired.
The published account does not name the abused driver, identify individual EDR products or provide affected product versions. Organisations should therefore avoid assuming that only one endpoint security vendor is exposed. The important detection context is the combination of vulnerable driver activity with the preceding ClickFix, WebDAV and DLL side-loading stages.
Multiple payload branches increase the impact
The crypto stealer is only one possible outcome. Cisco Talos also identified a branch capable of giving an operator remote control of an affected system. This creates a path from a deceptive webpage to persistent access, rather than a single attempt to collect browser data.
The branches demonstrate the flexibility of the ClearFake infrastructure. The initial fake CAPTCHA and remote-loader process can lead to payloads selected for different objectives, including credential theft, cryptocurrency diversion and operator-controlled access.
Current reporting confirms observed activity connected to the April 2026 investigation and characterises it as a broader theft campaign. It does not provide a total number of affected organisations, a list of compromised websites or a campaign end date. The operation should therefore be treated as active unless subsequent intelligence confirms otherwise.
Why the ClearFake crypto stealer matters
The campaign is significant because it links a simple social engineering prompt to several established defence evasion methods. Users may believe they are completing a standard CAPTCHA, while the requested command begins a chain that can undermine endpoint controls and alter cryptocurrency transactions.
It also shows why alerts should be assessed as a sequence. A fake verification page, WebDAV access, remote library execution, a signed Chrome component loading an adjacent DLL and vulnerable driver activity may each provide evidence of the same ClearFake crypto stealer intrusion.
Actions organisations should take
Security teams should review telemetry for unexpected WebDAV connections and remote library execution, particularly where activity follows browser use. They should also investigate signed applications loading DLLs from unusual directories or archives.
- Block known ClearFake infrastructure and compromised website indicators supplied through trusted threat intelligence.
- Monitor for commands copied from websites and executed through Windows utilities.
- Restrict or alert on vulnerable driver loading where operationally possible.
- Correlate EDR service disruption with WebDAV, archive extraction and DLL side-loading events.
- Warn staff that legitimate CAPTCHA checks do not require commands to be copied and run.
Cryptocurrency users should verify the full destination address immediately before approving a transaction. If ClearFake crypto stealer activity is suspected, organisations should isolate the device and investigate every stage of the chain, not only the browser event.
Originally reported by cybersecuritynews.com.







