Threat Actor
ClearFake
- First Reported
- Aug 13, 2026
- Latest Reported
- Sep 21, 2026
Reported Context (2)
- Named as a ClickFix malware-distribution cluster competing alongside ErrTraffic. Sekoia Finds Exvicy ClickFix Framework Reuses ErrTraffic Code
- Named as a threat actor using compromised websites to steal credentials and sell them for further exploitation. Expired malicious domains let three actors redirect compromised-site visitors to scams and malware
Malware (4)
People (2)
Threat Actors (11)
MITRE ATT&CK (14)
Vendors (11)
Products (12)
Tools (3)
Industries (4)
Countries (3)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.