Meet IClickFix: a widespread WordPress-targeting framework using the ClickFix tactic
ID: 68bca0d4-5770-5eec-b004-a89fc96662a7
STIX ID: report--68bca0d4-5770-5eec-b004-a89fc96662a7
Feed Name: Sekoia.io Blog
Date Published: 2026-01-29
Date Updated: 2026-04-29
Author: Quentin Bourgue, Amaury G. and Sekoia TDR
Sekoia.io TDR uncovered and analyzed IClickFix, a multi-stage JavaScript framework active since late 2024 that injects an ic-tracker-js tag into compromised WordPress sites (over 3,800 observed) to display a fake Cloudflare Turnstile ClickFix lure; victims are tricked into pasting a clipboard command that runs a PowerShell dropper, resulting in the deployment of NetSupport RAT (and historically Emmenhtal Loader/XFiles Stealer). The report includes technical analysis of the injection and redirection chain (YOURLS-based TDS), infection stages, full IoCs (domains, IPs, file hashes), and YARA rules to detect the campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
