logo

RST TI Report Digest: 16 Mar 2026

ID: 537a3de1-e8ff-524c-b406-46bf6b765a5d

STIX ID: report--537a3de1-e8ff-524c-b406-46bf6b765a5d

Feed Name: RST Cloud Blog

Threat Score
75/100

Date Published: 2026-03-17

Date Updated: 2026-04-29

Author: RST Cloud

...
...

Rapid7 Labs identified an active global campaign starting in December 2025 that compromises legitimate WordPress sites to serve a ClickFix implant (masquerading as a Cloudflare CAPTCHA) which uses obfuscated JavaScript and PowerShell to fetch shellcode and deploy multiple infostealers (Vidar, VodkaStealer, Impure and others) via Donut-based loaders; the operation has affected over 250 sites across 12 countries and the report includes extensive IOCs (IPs, domains, URLs, and hashes) for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.