logo

Crooks compromise WordPress sites to push infostealers via fake CAPTCHA prompts

ID: b6aa3a2c-6bfa-505d-bed1-603c6daf088e

STIX ID: report--b6aa3a2c-6bfa-505d-bed1-603c6daf088e

Feed Name: The Register (Security)

Threat Score
72/100

Date Published: 2026-03-10

Date Updated: 2026-04-26

Author: Carly Page

...
...

Researchers at Rapid7 uncovered a large-scale campaign where attackers injected malicious code into legitimate WordPress websites (including a US Senate candidate's site) to display fake Cloudflare CAPTCHA pages that instruct visitors to run commands; following these steps results in installation of infostealer malware that harvests browser credentials, cookies, and crypto wallet data. The operation has affected over 250 sites in at least 12 countries, appears automated and long-running (active since Dec 2025 with infrastructure dating back to mid-2025), and is tied to the ClickFix social-engineering playbook.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.