Threats · 183 days ago
Rapid7 tracked a campaign that compromised 250+ legitimate WordPress sites to inject a fake Cloudflare 'ClickFix' CAPTCHA that delivers a multi-stage Windows stealer. The malware runs mainly in memory and steals credentials and crypto wallets, enabling financial theft and follow-on intrusions
3 sources covering this story
ClickFix techniques evolve in new infostealer campaigns
Recent social engineering schemes involving WordPress and Microsoft’s Windows Terminal show that this relatively basic tactic is a growing threat.
Compromised WordPress Sites Deliver ClickFix Attacks
Over 250 legitimate websites, including news outlets and a US Senate candidate’s official webpage, been compromised to infect visitors with infostealers, warn Rapid7 researchers
When Trusted Websites Turn Malicious: WordPress Compromises Advance Global Stealer Operation
Rapid7 Labs has identified an ongoing, widespread compromise of legitimate WordPress websites, misused by an unidentified threat actor to inject a ClickFix implant (impersonating a Cloudflare human verification challenge [CAPTCHA]).
Part of the PlainSec briefing for 2026-03-19