logo

Compromised WordPress Sites Deliver ClickFix Attacks in Global Infostealer Campaign

ID: ed9a60fe-1b42-5ae9-a07c-cdf9e2b44c55

STIX ID: report--ed9a60fe-1b42-5ae9-a07c-cdf9e2b44c55

Feed Name: Infosecurity Magazine (News)

Threat Score
72/100

Date Published: 2026-03-11

Date Updated: 2026-04-22

...
...

Rapid7 warns of a global cyber-criminal campaign that has compromised 250+ legitimate WordPress sites in at least 12 countries and uses convincing fake Cloudflare captcha pages plus ClickFix social-engineering prompts to trick visitors into running commands that install infostealer malware (Vidar, Impure, Vodka, Double Donut) to harvest credentials and financial data; site compromises may stem from plugin/theme vulnerabilities, stolen credentials, or brute-force admin access, and Rapid7 advises patching, strong passwords, MFA and avoiding running untrusted code.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.