Oltre 250 Siti WordPress Diffondono ClickFix CAPTCHA Infostealer
Rapid7 segnala la compromissione di oltre 250 siti WordPress legittimi. I siti mostrano un falso CAPTCHA ClickFix che induce gli utenti a incollare un comando nella Windows Run, avviando un infostealer in-memory. Payload osservati: Vidar, Impure, Vodka e Double Donut; rubano credenziali e wallet.
Over 250 legitimate websites, including news outlets and a US Senate candidate’s official webpage, been compromised to infect visitors with infostealers, warn Rapid7 researchers
When Trusted Websites Turn Malicious: WordPress Compromises Advance Global Stealer Operation
Rapid7 Labs has identified an ongoing, widespread compromise of legitimate WordPress websites, misused by an unidentified threat actor to inject a ClickFix implant (impersonating a Cloudflare human verification challenge [CAPTCHA]).