The CAPTCHA Trap: How a Global ‘ClickFix’ Campaign Weaponizes WordPress to Drain Digital Wallets
ID: 4f31e6ca-bcec-5be8-8f32-fbd1c1e4767f
STIX ID: report--4f31e6ca-bcec-5be8-8f32-fbd1c1e4767f
Feed Name: securityonline.info
Rapid7 researchers uncovered a widespread campaign that compromises over 250 legitimate WordPress sites in at least 12 countries to inject a fake Cloudflare CAPTCHA (ClickFix) which tricks visitors into running a Win+R/PowerShell command. That command loads an in-memory DoubleDonut loader delivering a rotating set of infostealers—including Vidar Stealer v2, Impure Stealer, and a custom VodkaStealer—that exfiltrate credentials and drain digital wallets while employing strong anti-analysis and geofencing checks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
