Malwarebox public intelligence surface
IIM Feeds for adversary infrastructure chains.
Published IIM chains from MANTIS, shaped for humans first: browse actor infrastructure, compare role flows, open evidence, and export the canonical JSON when you need the raw model.
IIM Atlas Board
Role matrix of the published feed
| chain | actor | conf | entry | redirector | staging | payload | c2 | edges | published |
|---|---|---|---|---|---|---|---|---|---|
redcanary.2026.clearfake-clickfix-paste-and-run-acr-stealer
ClearFake JavaScript injection on compromised sites driving fake-CAPTCHA ClickFix paste-and-run to ACR Stealer
|
ClearFake | confirmed | 1 <compromised website with injected JS> | 1 injected JavaScript serving fake-CA... | 1 <remote payload-retrieval host> | 1 ACR Stealer (MaaS infostealer) | 1 <ACR Stealer C2 endpoint> | 5e / 4r | 2026-05-30 21:31:45 |
Technique pressure
top observed IIM techniquesActor surface
published chain attributionredcanary.2026.clearfake-clickfix-paste-and-run-acr-stealer
ClearFake JavaScript injection on compromised sites driving fake-CAPTCHA ClickFix paste-and-run to ACR Stealer
IIM chain for the ClearFake activity cluster, ranked the most prevalent threat in Red Canary's May 2026 intelligence insights. ClearFake injects JavaScript into compromised websites to deliver malware via drive-by techniques, frequently using fake CAPTCHA lures that trick users into executing code via malicious copy-and-paste (paste-and-run / ClickFix / fakeCAPTCHA). Red Canary reports ClearFake has delivered multiple payloads over time including ArechClient2 and LummaC2, and most recently ACR Stealer, a malware-as-a-service infostealer. The paste-and-run user-execution step is endpoint behaviour and is recorded only under attack_annotations.