The “IClickFix” Trap: 3,800+ WordPress Sites Poisoned by Fake CAPTCHAs
ID: 928679f9-ced4-5085-8673-e3159f8ac8a3
STIX ID: report--928679f9-ced4-5085-8673-e3159f8ac8a3
Feed Name: securityonline.info
Sekoia TDR uncovered the IClickFix watering-hole campaign that has injected malicious JavaScript into thousands (~3,800+) WordPress sites since late 2024, presenting a fake Cloudflare Turnstile CAPTCHA that tricks users into copying and running PowerShell "fix" commands; those commands download payloads such as NetSupport RAT, Emmenhtal Loader, and XFiles Stealer while the operators use YOURLS as a TDS, an ic-tracker-js tag for victim filtering, and frequent toolkit updates to scale and evade detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
