Threats & Adversaries · Credential Theft
Threat actors compromised more than 250 WordPress sites to inject fake Cloudflare 'ClickFix' CAPTCHA prompts that trick visitors into running a multi-stage Windows infostealer.
3 sources · Mar 16
CSO Online
ClickFix techniques evolve in new infostealer campaigns
Recent social engineering schemes involving WordPress and Microsoft’s Windows Terminal show that this relatively basic tactic is a growing threat.
originalInfosecurity Magazine
Compromised WordPress Sites Deliver ClickFix Attacks
Over 250 legitimate websites, including news outlets and a US Senate candidate’s official webpage, been compromised to infect visitors with infostealers, warn Rapid7 researchers
originalRapid7
When Trusted Websites Turn Malicious: WordPress Compromises Advance Global Stealer Operation
Rapid7 Labs has identified an ongoing, widespread compromise of legitimate WordPress websites, misused by an unidentified threat actor to inject a ClickFix implant (impersonating a Cloudflare human verification challenge [CAPTCHA]).
originalPart of the PlainSec briefing for 2026-03-16
Every edition of this story: Attackers Weaponize 250+ WordPress Sites to Steal Credentials