Over 250 WordPress Sites Serve ClickFix CAPTCHA Infostealers
The ClickFix prompt tricks users into pasting a Windows Run command that launches in-memory infostealers. Observed payloads (Vidar, Impure, Vodka, Double Donut) steal credentials and crypto wallets.
Over 250 legitimate websites, including news outlets and a US Senate candidate’s official webpage, been compromised to infect visitors with infostealers, warn Rapid7 researchers
When Trusted Websites Turn Malicious: WordPress Compromises Advance Global Stealer Operation
Rapid7 Labs has identified an ongoing, widespread compromise of legitimate WordPress websites, misused by an unidentified threat actor to inject a ClickFix implant (impersonating a Cloudflare human verification challenge [CAPTCHA]).