ClearFake Steals Cryptocurrency with Vulnerable Driver Attack
A sophisticated cyberattack operation, known as ClearFake, has been discovered to use a vulnerable driver to disable endpoint detection and response (EDR) security tools. This allows attackers to steal cryptocurrency and credentials from compromised websites.
The attack begins with injected browser code, blockchain-hosted instructions, and a fake CAPTCHA prompt. When a user follows the steps, a remote loader retrieves and runs a disguised library through WebDAV.
Cisco Talos analysts identified the activity after seeing unusual remote library execution at a Ukrainian government organization in April 2026. They assess the observed attacks were part of a broader theft operation, not one campaign aimed at that organization.