Ghost CMS Vulnerability Exploited to Infect 700 Sites With ClickFix Malware
ID: 0e53d07d-c17b-5d04-b568-a26e2e3173a6
STIX ID: report--0e53d07d-c17b-5d04-b568-a26e2e3173a6
Feed Name: GBHackers
Researchers observed active exploitation of a critical Ghost CMS SQL injection (CVE-2026-26980) that allows attackers to extract Admin API keys, modify site content at scale, and inject JavaScript loaders that chain into fingerprinting, social-engineered CAPTCHA prompts, and delivery of ClickFix-style malware (including data-stealing variants) across 700+ domains spanning academia, media, and SaaS. The campaign uses automated reinfection, infrastructure rotation, and legitimate utilities (e.g., rundll32) to execute payloads, persistent backdoors, and C2 communications; immediate patching, API key rotation, and content/log inspections are strongly advised.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
