Crooks compromise WordPress sites to push infostealers via fake CAPTCHA prompts
ID: b6aa3a2c-6bfa-505d-bed1-603c6daf088e
STIX ID: report--b6aa3a2c-6bfa-505d-bed1-603c6daf088e
Feed Name: The Register (Security)
Researchers at Rapid7 uncovered a large-scale campaign where attackers injected malicious code into legitimate WordPress websites (including a US Senate candidate's site) to display fake Cloudflare CAPTCHA pages that instruct visitors to run commands; following these steps results in installation of infostealer malware that harvests browser credentials, cookies, and crypto wallet data. The operation has affected over 250 sites in at least 12 countries, appears automated and long-running (active since Dec 2025 with infrastructure dating back to mid-2025), and is tied to the ClickFix social-engineering playbook.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
