Ghost CMS Mass Compromised via CVE-2026-26980, Now Fueling ClickFix Attacks
ID: 3d4bc7c4-e509-55e9-9fd8-c241880fb10f
STIX ID: report--3d4bc7c4-e509-55e9-9fd8-c241880fb10f
Feed Name: QiAnXin XLab
Threat Score
XLab detected a large-scale Ghost CMS poisoning campaign exploiting CVE-2026-26980 to extract Admin API keys and inject JavaScript loaders across 700+ domains; attackers used cloaking services and FakeCaptcha social engineering to distribute multi-stage payloads (including a stealer trojan and persistent Electron backdoor), multiple attack groups are active, and the report includes IoCs, sample analyses, detection checks, and remediation steps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
