{"id":4490,"date":"2025-06-07T10:03:50","date_gmt":"2025-06-07T10:03:50","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/06\/07\/new-clickfix-attack-exploits-fake-cloudflare-human-check-to-install-malware-silently\/"},"modified":"2025-06-07T10:03:50","modified_gmt":"2025-06-07T10:03:50","slug":"new-clickfix-attack-exploits-fake-cloudflare-human-check-to-install-malware-silently","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/06\/07\/new-clickfix-attack-exploits-fake-cloudflare-human-check-to-install-malware-silently\/","title":{"rendered":"New ClickFix Attack Exploits Fake Cloudflare Human Check to Install Malware Silently"},"content":{"rendered":"<p>    New ClickFix Attack Exploits Fake Cloudflare Human Check to Install Malware Silently<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated new social engineering attack campaign has emerged that exploits users\u2019 familiarity with routine security checks to deliver malware through deceptive Cloudflare verification pages.<\/p>\n<p>The ClickFix attack technique represents a concerning evolution in phishing methodology, abandoning traditional file downloads in favor of manipulating users into executing malicious commands directly on their own systems.<\/p>\n<p>The attack operates by presenting victims with what appears to be a legitimate Cloudflare Turnstile interface, complete with official branding, authentic wording, and dynamically generated Ray IDs that reinforce the illusion of legitimacy.<\/p>\n<p>When users encounter these <a href=\"https:\/\/cybersecuritynews.com\/fake-captcha-delivers-eddiestealer\/\" target=\"_blank\" rel=\"noreferrer noopener\">fake verification<\/a> pages, they see familiar messages such as \u201cChecking if the site connection is secure \u2013 Verify you are human,\u201d identical to what they would expect from genuine Cloudflare protection mechanisms.<\/p>\n<p>This calculated mimicry exploits verification fatigue, a phenomenon where internet users have become conditioned to quickly click through security prompts without careful examination.<\/p>\n<p>SlashNext researchers <a href=\"https:\/\/slashnext.com\/blog\/decoding-clickfix-lessons-from-the-latest-browser-based-phish\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> this emerging threat as part of their ongoing threat intelligence operations, noting the attack\u2019s particularly insidious approach to bypassing traditional security measures.<\/p>\n<p>The technique has proven remarkably effective because it leverages user trust in established security providers while requiring no sophisticated exploits or zero-day vulnerabilities.<\/p>\n<p>Instead, the attack relies on convincing users to voluntarily execute malicious code under the guise of completing a routine verification process.<\/p>\n<p>The campaign has been observed delivering various malware families, including information stealers like Lumma and Stealc, as well as remote access trojans such as NetSupport Manager.<\/p>\n<p>The attack\u2019s success stems from its ability to bypass traditional <a href=\"https:\/\/cybersecuritynews.com\/googles-oauth-system-flaws\/\" target=\"_blank\" rel=\"noreferrer noopener\">security filters<\/a> by having users execute legitimate system utilities with malicious parameters, rather than downloading suspicious executable files.<\/p>\n<p>This approach effectively circumvents many endpoint protection solutions that focus on scanning downloaded binaries.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Technical Infection Mechanism and Clipboard Exploitation<\/strong><\/h2>\n<p>The ClickFix attack employs a sophisticated clipboard manipulation technique that occurs entirely within the victim\u2019s browser environment.<\/p>\n<p>When users interact with the fake Cloudflare verification page by clicking the \u201cVerify you are human\u201d checkbox, the malicious webpage\u2019s embedded JavaScript immediately executes a hidden script that creates an invisible text element containing an obfuscated PowerShell command.<\/p>\n<p>This command is automatically copied to the user\u2019s clipboard using standard web APIs, leaving no visible indication of the clipboard compromise.<\/p>\n<p>The attack page subsequently presents users with seemingly legitimate verification steps that instruct them to press specific key combinations: Windows+R to open the Run dialog box, followed by Ctrl+V to paste the clipboard contents, and finally Enter to execute the command.<\/p>\n<p>By this point, the dangerous PowerShell payload is already residing in the user\u2019s clipboard, waiting to be unknowingly executed.<\/p>\n<p>The malicious command is typically structured as a one-liner that retrieves and executes second-stage malware from remote servers, often utilizing Base64 encoding or other obfuscation techniques to avoid detection.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgR5hf_e7ZouQ5DgWJQuFoH8_9sg1fYM_ppp5-1iQdAG4jIAw75l1LszGGrHAIT5326kfGuOI677O2sZrFfmmR78e9qHUS5WPuypM0SyjbJtXVxnCVkV5CUWxoVZNr-mKVBmLP4bnkNeOlmIAnsNlVUkmN4WL19lP2vhtErBXMuo5pXPJo29mfF2eo1DlE\/s16000\/The%2520fake%2520Cloudflare%2520page%2520shown%2520at%2520the%2520start%2520of%2520the%2520attack%2520%28Source%2520-%2520SlashNext%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">The fake Cloudflare page shown at the start of the attack (Source \u2013 SlashNext)<\/figcaption><\/figure>\n<\/div>\n<p>The initial fake Cloudflare page that users encounter at the beginning of the attack sequence.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj6gKiyILoYUtffMkBaNARPeeOUxGf1v1uYe76v2QNlnzGALRzysSYpW14hTblbtqxMpo6K30zQlIF2MJTKRInezjmRe7KOPiTn_UbTxzD8up62VmxuEgzUhCV7V4mxFILv992R_1D-m1Qz7Q0WHzDxq023tgDutcw6Dusfpxq7I4n4oB-MX5c8NtIZsm4\/s16000\/The%2520step-by-step%2520instructions%2520that%2520trick%2520users%2520into%2520executing%2520malware%2520%28Source%2520-%2520SlashNext%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">The step-by-step instructions that trick users into executing malware (Source \u2013 SlashNext)<\/figcaption><\/figure>\n<\/div>\n<p>While this shows the step-by-step instructions that manipulate users into executing the malware payload.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEifXYuIpk6H2_2fCh0tlmJR7BU8PX6gmyfo44tCHmXWteJ5kvWg3jQ4yHLyHwh8UZ1YqEeVXxSw61JoW_lH7P0S0noI2mGCVR47DqQeYZg4UBMYfRRAxB2LEyXOvVgpBkHIlulye-dqx7nUoIEF9PvqzM9y1DaFzYyQx-LNunZQxKvsW7YfQtxNNskFzHw\/s16000\/A%2520hidden%2520PowerShell%2520command%2520copied%2520to%2520the%2520clipboard%2520%28Source%2520-%2520SlashNext%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">A hidden PowerShell command copied to the clipboard (Source \u2013 SlashNext)<\/figcaption><\/figure>\n<\/div>\n<p>Besides this, this depicts the hidden PowerShell command that gets copied to the user\u2019s clipboard during the verification process.<\/p>\n<p>The entire attack infrastructure is contained within a single, self-contained HTML file that embeds all necessary images, styles, and scripts locally, enabling the <a href=\"https:\/\/cybersecuritynews.com\/browser-locker-ransomware-a-fake-page-that-threatens-user-and-demands-ransom\/\" target=\"_blank\" rel=\"noreferrer noopener\">fake page<\/a> to load seamlessly on the attacker\u2019s chosen domain without requiring external resources that might trigger security warnings.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\"><strong>Speed up and enrich threat investigations with Threat Intelligence Lookup! -&gt;\u00a0<a href=\"https:\/\/intelligence.any.run\/plans?utm_source=csn_jun&amp;utm_medium=article&amp;utm_campaign=cyber-ti-guide-for-cisos&amp;utm_content=plans2&amp;utm_term=030625\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>50 trial search requests<\/strong><\/a><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/new-clickfix-attack-exploits-fake-cloudflare-human-check\/\">New ClickFix Attack Exploits Fake Cloudflare Human Check to Install Malware Silently<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/new-clickfix-attack-exploits-fake-cloudflare-human-check\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New ClickFix Attack Exploits Fake Cloudflare Human Check to Install Malware Silently A sophisticated new social engineering attack campaign has emerged that exploits users\u2019 familiarity with routine security checks to deliver malware through deceptive Cloudflare verification pages. The ClickFix attack technique represents a concerning evolution in phishing methodology, abandoning traditional file downloads in favor of [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-4490","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4490"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=4490"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4490\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=4490"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=4490"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=4490"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}