Threat actors are compromising legitimate websites—particularly WordPress sites—and injecting fake Cloudflare, reCAPTCHA, browser-error, update, and support-verification pages that persuade visitors to paste browser-preloaded commands into Windows Run, PowerShell, or macOS Terminal. More than 250 compromised sites across at least 12 countries were identified in one automated campaign, while Australia’s ACSC warned that similar activity is targeting organizations across multiple sectors. Operators increasingly use living-off-the-land execution, including mshta, curl, cmdkey, and regsvr32, alongside in-memory payloads, DLL side-loading, scheduled tasks, registry persistence, remote SMB shares, and blockchain- or Cloudflare Pages-hosted staging to reduce disk artifacts and evade controls.
The campaigns deliver a broad and evolving payload set, including StealC, Vidar Stealer, Lumma Stealer, Venom Stealer, NetSupport RAT, Remcos, Sectop RAT, and proxy-enabled remote access tooling such as PySoxy. Stolen data includes browser credentials and cookies, cryptocurrency wallets, VPN configurations, email and gaming credentials, system profiles, and screenshots; some malware maintains access and continuously harvests newly saved credentials. Organizations should prohibit users from executing commands supplied by websites, restrict PowerShell and Windows Run where feasible, apply application control and least privilege, patch internet-facing WordPress deployments, and hunt for anomalous browser-to-clipboard activity, PowerShell or HTA execution, suspicious scheduled tasks and Run keys, remote DLL loading, and unexpected proxy processes.

Pull IOCs and campaign context straight into your stack.
32 events from the most recent confirmed update back to the earliest known activity.
A Cloudflare Pages site posing as an Adobe activation guide used a ClickFix PowerShell lure to download an obfuscated JavaScript downloader and execute %TEMP%\putty.exe. The downloader removed itself and the payload after execution, while resulting network activity was assessed as consistent with Lumma Stealer.
Australia’s ACSC warned that compromised WordPress sites were being used to target Australian organizations with ClickFix lures that deploy Vidar Stealer. The campaign injected JavaScript to replace legitimate content with fake Cloudflare verification prompts and used dead-drop resolvers, including Telegram bots and Steam profiles, for initial C2 discovery.
CyberProof published findings on a ClickFix variant that replaced PowerShell with cmdkey and regsvr32. The pasted command stored credentials for an attacker IP, loaded a DLL from an SMB share, and created the “RunNotepadNow” scheduled task using a remotely hosted XML definition.
ReliaQuest observed a ClickFix intrusion in which a user-executed PowerShell stager created scheduled-task persistence, performed domain reconnaissance, and deployed PySoxy as a second encrypted access channel. The scheduled task continued attempting to relaunch the chain after endpoint controls blocked both command-and-control paths.
Recorded Future published findings on five ClickFix clusters targeting Windows and macOS through impersonated verification pages. The clusters used native tools for execution and delivered payloads including NetSupport RAT, Odyssey Stealer, Lumma Stealer, and MacSync; the report named potential links to APT28 and North Korea’s PurpleBravo.
Internet Storm Center observed SmartApeSG, also tracked as ZPHP and HANEYMANEY, use a fake-CAPTCHA ClickFix lure to deliver Remcos RAT, NetSupport RAT, StealC, and Sectop RAT to a single host. Several delivery archives used DLL side-loading, while the initial Remcos HTA downloader was removed after execution.
Breakglass analyzed a ClickFix campaign using applicationhost17.com to deliver NetSupport RAT v14.10 through PowerShell and MSI installers. The malware persisted through an HKCU Run key and beaconed to 172.94.9.4:443 using NetSupport HTTP traffic.
A March 9 Venom Stealer update added a File Password and Seed Finder that scans local filesystems for seed phrases. The malware-as-a-service platform incorporated ClickFix templates and persisted to monitor Chrome for newly saved credentials.
The domain applicationhost17.com, used for a NetSupport RAT v14.10 ClickFix campaign, was registered through Njalla privacy service. Its DNS moved from M247-hosted Frankfurt infrastructure to a Moscow-hosted server between March 11 and 12.
Scarlet Goldfinch briefly stopped checking for Notepad and executed mshta directly. It later used cmd and curl to download an HTA before executing it with mshta, adding delayed environment-variable expansion and caret-based obfuscation.
LevelBlue documented ErrTraffic V3 using a WordPress must-use-plugin backdoor, injected obfuscated JavaScript, and Polygon smart-contract lookups to obtain attacker infrastructure. The framework generated ClickFix commands on compromised sites and supported multilingual fake BSOD, reCAPTCHA, and Cloudflare lures.
Researchers identified a fake Cloudflare CAPTCHA campaign on compromised websites that tricked Windows users into manually executing PowerShell and installed StealC through Donut-generated shellcode and svchost.exe process injection.
Scarlet Goldfinch replaced its use of forfiles with an “if exist” check for Notepad in Windows System32, while continuing to use mshta as its initial-payload downloader.
ErrTraffic V3, a traffic-distribution system built to support ClickFix campaigns, was advertised in underground forums and remained under active development. It targeted WordPress sites and supported multi-platform payload delivery.
Scarlet Goldfinch’s sixth observed paste-and-run epoch began in late December 2025 and continued into mid-January 2026. The activity used Remcos as an intermediate payload to deliver and establish persistence for NetSupport Manager.
A large-scale campaign compromising WordPress sites to serve fake Cloudflare CAPTCHA prompts was active in its current form by December 2025. The campaign used ClickFix prompts to deliver infostealers that targeted browser credentials, cookies, and cryptocurrency-wallet data.
An earlier ClickFix campaign targeted restaurant reservation systems and later served as a behavioral comparison point for a 2026 fake-CAPTCHA infostealer campaign.
NCC Group investigated a drive-by compromise in which a user was redirected to a ClickFix fake CAPTCHA page and tricked into running PowerShell that downloaded Lumma-related payloads. The intrusion targeted Edge and Chrome browser credential stores and used mshta, AutoIt, and obfuscated PowerShell.
Sekoia identified more than 9,300 compromised websites associated with ClearFake through a single query. The framework alternated between fake Cloudflare Turnstile and reCAPTCHA lures and used Emmenhtal Loader v2 in the observed chain.
Researchers observed the newly discovered ARKANIX Stealer active and distributed through Discord communities and underground forums while masquerading as legitimate utilities.
ClearFake distributed Vidar Stealer during its evolving ClickFix and blockchain-based delivery activity.
ClearFake added fake reCAPTCHA and Cloudflare Turnstile lures alongside fake technical-issue prompts, encrypted ClickFix HTML on Cloudflare Pages, and expanded Web3-based staging.
Two contracts used in a later ClearFake chain were uploaded to a Binance Smart Chain wallet, supporting retrieval of lure URLs, encryption keys, and ClickFix commands.
John Hammond published a proof-of-concept harness recreating the ClickFix/Emmenhtal fake-reCAPTCHA flow, including clipboard preloading and a sample HTA that launches Windows Calculator.
ClearFake injected scripts began directly contacting Binance Smart Chain to retrieve next-stage payloads, while targeting users across 44 languages and distributing Lumma Stealer.
ClearFake adopted ClickFix social engineering, using fake browser error messages to persuade users to execute malicious PowerShell commands.
A “Verify you are human” reCAPTCHA-style lure was observed in the wild around August and September 2024, preloading a malicious command into victims’ clipboards for execution through the Windows Run dialog.
A ClearFake variant used Binance Smart Chain smart contracts to obtain second-stage JavaScript, with campaign chains delivering loaders and Lumma, StealC, and AMOS stealers.
ClearFake emerged as a malicious JavaScript framework on compromised websites, initially using fake browser-update pages to induce downloads of counterfeit updates.
ClickFix was first documented in late 2023 as a social-engineering technique that induces victims to manually execute attacker-provided commands.
An Astro-site operator reported an unexpected malicious reCAPTCHA prompt on a static site with no such functionality and concluded that a compromised Cloudflare account injected the content at the delivery layer. The incident was characterized as a living-off-the-land pastejacking operation using edge interception.
Microsoft reported an updated ClickFix technique in which the victim-pasted initial command uses nslookup to retrieve content, then parses and executes the response rather than launching PowerShell directly at the outset.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 356 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
50 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcemalwr-analysis.com
Open sourcegithub.com
Open sourcecommunity.gurucul.com
Open sourcereliaquest.com
Open sourcebinarydefense.com
Open sourcesophos.com
Open sourcecert.pl
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.