Malwarebox public intelligence surface

IIM Feeds for adversary infrastructure chains.

Published IIM chains from MANTIS, shaped for humans first: browse actor infrastructure, compare role flows, open evidence, and export the canonical JSON when you need the raw model.

community intake

Submit sourced IIM chains for review

local storage, validator, anti-spam cap and contribution board

Analysts can paste a chain directly into the public surface, pass validation and store it as a dated local JSON file for manual Malwarebox review.

source link required 1000/day global cap duplicate filter captcha local
confirmed32
likely7
tentative0
needs review12

IIM Atlas Board

Role matrix of the published feed

10 chains per page, each row opens the full chain view
chain actor conf entryredirectorstagingpayloadc2 edges published
redcanary.2026.clearfake-clickfix-paste-and-run-acr-stealer ClearFake JavaScript injection on compromised sites driving fake-CAPTCHA ClickFix paste-and-run to ACR Stealer ClearFake confirmed 1 <compromised website with injected JS> 1 injected JavaScript serving fake-CA... 1 <remote payload-retrieval host> 1 ACR Stealer (MaaS infostealer) 1 <ACR Stealer C2 endpoint> 5e / 4r 2026-05-30 21:31:45
Showing 11 of 1 matching chains
Reset
Page 1 of 1. Showing 11 of 1 matching chains, 39 total.

redcanary.2026.clearfake-clickfix-paste-and-run-acr-stealer

ClearFake JavaScript injection on compromised sites driving fake-CAPTCHA ClickFix paste-and-run to ACR Stealer

confirmed

IIM chain for the ClearFake activity cluster, ranked the most prevalent threat in Red Canary's May 2026 intelligence insights. ClearFake injects JavaScript into compromised websites to deliver malware via drive-by techniques, frequently using fake CAPTCHA lures that trick users into executing code via malicious copy-and-paste (paste-and-run / ClickFix / fakeCAPTCHA). Red Canary reports ClearFake has delivered multiple payloads over time including ArechClient2 and LummaC2, and most recently ACR Stealer, a malware-as-a-service infostealer. The paste-and-run user-execution step is endpoint behaviour and is recorded only under attack_annotations.

entry redirector staging payload c2
ClearFake 5 entities 4 relations 2026-05-30 21:31:45
IIM-T004 IIM-T015
Open chain analysis