Red Canary Intelligence Insights July 2026: ClearFake Leads Third Straight Month Amid CastleLoader Debut and Caret-Obfuscated Paste-and-Run Campaigns — Threadlinqs Intelligence
As of 2026-07-23, Red Canary Intelligence Insights July 2026: ClearFake Leads Third Straight Month Amid CastleLoader Debut and Caret-Obfuscated Paste-and-Run Campaigns is a medium-severity malware threat attributed to GrayBravo, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 41 indicators of compromise.
Threat ID: TL-2026-1658 · Severity: MEDIUM · Status: ACTIVE · Category: MALWARE
Attribution: GrayBravo · FINANCIAL
Red Canary's June 2026 threat prevalence ranking shows ClearFake retaining the #1 spot for a third consecutive month via fake-CAPTCHA ClickFix (T1204.004) drive-by lures now backed by EtherHiding
Red Canary's July 2026 Intelligence Insights report (covering June 2026 telemetry) confirms ClearFake as the most prevalent threat observed across customer environments for a third consecutive month. ClearFake is a JavaScript injection cluster that compromises legitimate WordPress sites to serve fake CAPTCHA / fake browser-update overlays that trick victims into pasting and executing attacker-supplied commands (ClickFix / T1204.004 Malicious Copy and Paste). In 2026 ClearFake operators (tracked historically to Storm-1607/Storm-0426/Storm-0249 infrastructure and the TA571-linked ClearFake compromise group) have adopted EtherHiding, storing payload-routing JavaScript directly inside immutable BNB Smart Chain (BSC) testnet smart contracts, making the delivery infrastructure effectively takedown-resistant. Confirmed final-stage payloads from the EtherHiding chain include SectopRAT (.NET browser-hijacking RAT) and ACRStealer (C++ infostealer), delivered via OS-aware branching for Windows and macOS victims.
KongTuke (aka Chaya_002 / LandUpdate808 / TAG-124), ranked #2 and showing a significant June 2026 activity increase, is a traffic distribution system that injects malicious JavaScript into compromised WordPress installations to serve ClickFix-family lures — FakeCAPTCHA, FileFix, and the newer CrashFix variant, which uses a malicious Chrome extension masquerading as an ad blocker to intentionally crash the browser and coerce the victim into running a fraudulent "security scan" command. KongTuke traffic has been linked to delivery of LummaC2, MintsLoader, D3F@ck Loader, Mocha Manakin, WARMCOOKIE, the new Mistic backdoor, Python-based modeloRAT, and downstream Rhysida/Interlock ransomware deployment.
CastleLoader, debuting in the top 10 at rank #5, is a malware-as-a-service (MaaS) loader operated by TAG-150 (Recorded Future Insikt Group attribution), active since at least March 2025 and first documented by PRODAFT in July 2025 (also tracked as CastleBot). Distribution is primarily via Cloudflare-themed ClickFix phishing pages and fraudulent GitHub repositories impersonating legitimate applications, plus SEO-poisoned fake download portals and a BackgroundFix campaign (April 2026) using fake background-image-removal utility sites. The infection chain begins with caret-obfuscated (^) command strings invoking the living-off-the-land binary finger.exe against an attacker-controlled TCP/79 daemon (Signed Binary Proxy Execution) to retrieve a Bring-Your-Own-Interpreter (BYOI) stage: a portable, unmodified CPython or IronPython interpreter renamed to a random numeric filename, deployed alongside a Base64/zlib-compressed Python script. That script is wrapped in an additional UTF-32 encoding layer with Cyrillic-character substitution before being RC4-decrypted and shellcode-injected into python.exe/pythonw.exe, executing entirely in memory. The resulting five-stage kill chain (clipboard execution -> shellcode stager with PEB-walking/DJB2 API hashing -> PE loader using direct NtAllocateVirtualMemory calls and PEB_LDR_DATA manipulation to evade EDR hooks, including an NtManageHotPatch hook for Windows 11 24H2 -> ChaCha20-encrypted core backdoor) culminates in delivery of CastleRAT (Python variant aka PyNightshade/NightshadeC2, and a more capable C variant with keylogging, screenshot capture, and cryptocurrency-clipper functionality), NetSupport Manager RAT, and previously reported payloads including DeerStealer, RedLine, StealC, SectopRAT, MonsterV2, and WARMCOOKIE. C2 uses a four-tier architecture (victim-facing servers, tiered VPS relays, backup servers) with Steam Community profiles used as dead-drop resolvers pointing to real C2 infrastructure, and IP-API geolocation lookups used for victim targeting.
Across all three clusters, Red Canary highlights a converging evasion toolkit: caret-character (^) obfuscation of cmd.exe strings to defeat literal-string detections, BYOI execution using portable interpreters to avoid file-based AV signatu
Target sectors: technology, professional services, job seekers employment platforms, general enterprise, government administration, finance, health
Target regions: North America, Europe, Global
Detections & IOCs
As of 2026-07-24, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 41 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, MEDIUM, threat intelligence, cybersecurity, T1189, T1566, T1204, T1204, T1204, T1059, T1059, T1059, T1106, T1053