VMTech
Discuss a project →

CTM360 Finds ClickFix Campaigns Across 17,000 Compromised URLs

CTM360 Finds ClickFix Campaigns Across 17,000 Compromised URLs

CTM360 has reported more than 17,000 infected URLs serving fake Cloudflare verification pages as part of ClickFix campaigns, with about 3,000 still actively delivering the lure when the research was conducted. The campaigns turn compromised, trusted websites into staging points that persuade visitors to paste a command into a native system interface.

ClickFix does not depend on a conventional exploit, an email attachment or a file downloaded directly by the victim. A page claims that a verification check, document, browser or device needs attention, copies a purported fix to the clipboard, and instructs the visitor to paste and run it. Microsoft attributed 47% of initial-access cases handled by its Defender Experts team in 2025 to ClickFix, ahead of conventional phishing.

Infrastructure designed to outlast domain blocks

CTM360 found that injected scripts on compromised sites can contain no attacker domain. Instead, a visitor's browser makes a free read-only request to a Polygon smart contract, which returns an encoded current lure hostname. This EtherHiding approach allowed three different lure hosts to be returned during a single day of analysis without changes to the infected websites.

The report also describes later-stage resolution through Telegram channel descriptions and a Steam profile page. These separate mechanisms make the campaign less dependent on any one hostname or takedown path. CTM360 concludes that blocking lure domains alone has little enduring value because operators can rotate them faster than blocklists can be distributed.

Targeting and payload delivery vary by visitor

The lure reports a visitor's operating system and version to the operator, which responds with the platforms to target and landing pages to serve. The examined configuration enabled Windows, retained completed macOS pages, and suppressed mobile visitors. CTM360 said the macOS branch was functional, including a disk-space maintenance pretext styled as an Apple support article, while the Linux slot was present but empty.

A traffic-distribution system can poll the operator about every 1.5 seconds and mark some sessions as verified without displaying malicious instructions. That means researchers, crawlers and sandboxes may receive a clean page while intended victims receive the ClickFix prompt.

In one recovered dropper, hardware and account details including machine GUID, volume serial, computer name, BIOS manufacturer, system model, GPU and username were base64-encoded into the download path. The command-and-control server could therefore decide whether to provide content for a particular machine. A separate analysis traced a chain through Telegram dead-drop resolvers and AES decryption to Vidar Stealer running inside a legitimately signed Microsoft binary by DLL side-loading.

WordPress cleanup and defensive controls

CTM360 found one compromised WordPress host where PHP appended a loader to every dynamic response, including HTML, RSS and JSON. The byte-identical output pointed to a must-use plugin that loads on every request and is absent from the standard plugin list. Researchers also found roughly two dozen administrator backdoors created by script, showing why deleting a visible script or a single account may leave the compromise intact.

The report identifies four recurring chokepoints: clipboard writing, opening an interpreter, outbound access from that interpreter, and persistence, collection or exfiltration. Blocking clipboard writes by default in managed browsers and requiring script interpreters and fetch utilities to use an authenticated proxy can disrupt this chain without relying on changing infrastructure indicators. For businesses, the practical implication is to pair rigorous WordPress incident cleanup with controls over what authenticated users can paste, execute and reach online.

#cybersecurity#clickfix#malware#websecurity
Open analytics
On the site 1 views
min read 4 24.09.2026
Instagram

CTM360 Finds ClickFix Campaigns Across 17,000 Compromised URLs

Open the post on Instagram ↗