{"id":9644,"date":"2026-01-04T10:03:44","date_gmt":"2026-01-04T10:03:44","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/01\/04\/infostealers-enable-attackers-to-hijack-legitimate-business-infrastructure-for-malware-hosting\/"},"modified":"2026-01-04T10:03:44","modified_gmt":"2026-01-04T10:03:44","slug":"infostealers-enable-attackers-to-hijack-legitimate-business-infrastructure-for-malware-hosting","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/01\/04\/infostealers-enable-attackers-to-hijack-legitimate-business-infrastructure-for-malware-hosting\/","title":{"rendered":"Infostealers Enable Attackers to Hijack Legitimate Business Infrastructure for Malware Hosting"},"content":{"rendered":"<p>    Infostealers Enable Attackers to Hijack Legitimate Business Infrastructure for Malware Hosting<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A dangerous cybercrime feedback loop has emerged where stolen credentials from <a href=\"https:\/\/cybersecuritynews.com\/new-jsceal-infostealer-malware-attacking-windows-systems\/\" target=\"_blank\" rel=\"noreferrer noopener\">infostealer malware<\/a> enable attackers to hijack legitimate business websites and turn them into malware distribution platforms. <\/p>\n<p>Recent research by the Hudson Rock Threat Intelligence Team reveals this self-sustaining cycle transforms victims into unwitting accomplices.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-the-clickfix-attack-method\"><strong>The ClickFix Attack Method<\/strong><\/h2>\n<p>Cybercriminals use a sophisticated social engineering technique called \u201cClickFix\u201d that tricks users into executing malicious code through their own actions. <\/p>\n<p>The attack begins when victims visit compromised websites showing fake security prompts mimicking Google reCAPTCHA or browser error messages. <\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"398\" src=\"https:\/\/i0.wp.com\/cybersecuritynews.com\/wp-content\/uploads\/2026\/01\/image-8-1024x398.png?resize=1024%2C398&#038;ssl=1\" alt=\"ClickFix Hunter aggregating 1,635 domains\" class=\"wp-image-138556\" srcset=\"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/01\/image-8-1024x398.png 1024w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/01\/image-8-300x117.png 300w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/01\/image-8-768x298.png 768w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/01\/image-8-1082x420.png 1082w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/01\/image-8-696x270.png 696w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/01\/image-8-1068x415.png 1068w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/01\/image-8-150x58.png 150w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/01\/image-8.png 1424w\" sizes=\"(max-width: 1024px) 100vw, 1024px\"><figcaption class=\"wp-element-caption\"><em>ClickFix Hunter aggregating 1,635 domains<\/em><\/figcaption><\/figure>\n<p>When users click these fraudulent alerts, malicious JavaScript silently copies a <a href=\"https:\/\/cybersecuritynews.com\/mastastealer-weaponizes-windows-lnk-files\/\" target=\"_blank\" rel=\"noreferrer noopener\">PowerShell command <\/a>to their clipboard.<\/p>\n<p>The fake prompt then instructs users to press Windows+R and paste the \u201cverification code\u201d using Ctrl+V. <\/p>\n<p>This executes the hidden command, downloading infostealer malware such as Lumma, Vidar, or Stealc, directly onto their system while bypassing traditional security controls.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"553\" src=\"https:\/\/i0.wp.com\/cybersecuritynews.com\/wp-content\/uploads\/2026\/01\/image-9-1024x553.png?resize=1024%2C553&#038;ssl=1\" alt=\"A classic ClickFix \u201cFake Captcha\u201d lure. The \u201cI am not a robot\u201d button is not a validation tool; it is a clipboard injector.\" class=\"wp-image-138558\" srcset=\"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/01\/image-9-1024x553.png 1024w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/01\/image-9-300x162.png 300w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/01\/image-9-768x415.png 768w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/01\/image-9-778x420.png 778w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/01\/image-9-696x376.png 696w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/01\/image-9-1068x577.png 1068w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/01\/image-9-150x81.png 150w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/01\/image-9.png 1359w\" sizes=\"(max-width: 1024px) 100vw, 1024px\"><figcaption class=\"wp-element-caption\"><em>A classic ClickFix \u201cFake Captcha\u201d lure. The \u201cI am not a robot\u201d button is not a validation tool; it is a clipboard injector.<\/em><\/figcaption><\/figure>\n<p>Research analyzing data from the ClickFix Hunter platform, which tracks over 1,600 active malicious domains, uncovered a startling pattern. <\/p>\n<p>Cross-referencing these domains with Hudson Rock\u2019s database of compromised credentials revealed 220 domains, approximately 13% that are simultaneously hosting ClickFix campaigns and have administrative credentials exposed in infostealer logs.<\/p>\n<p>This correlation proves a causal relationship, legitimate businesses whose administrators were infected by infostealers have had their websites hijacked to distribute the same malware that compromised them. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"933\" height=\"591\" src=\"https:\/\/i0.wp.com\/cybersecuritynews.com\/wp-content\/uploads\/2026\/01\/image-10.png?resize=933%2C591&#038;ssl=1\" alt=\"Definitive proof of the loop\" class=\"wp-image-138560\" srcset=\"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/01\/image-10.png 933w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/01\/image-10-300x190.png 300w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/01\/image-10-768x486.png 768w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/01\/image-10-663x420.png 663w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/01\/image-10-696x441.png 696w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/01\/image-10-150x95.png 150w\" sizes=\"(max-width: 933px) 100vw, 933px\"><figcaption class=\"wp-element-caption\"><em>Definitive proof of the loop<\/em><\/figcaption><\/figure>\n<\/div>\n<p>The stolen credentials include access to WordPress admin panels, cPanel hosting controls, and content management systems.<\/p>\n<p>Analysis of jrqsistemas.com demonstrates this pattern. The domain currently hosts an active ClickFix campaign. <\/p>\n<p>However, Hudson Rock intelligence indicates that the <a href=\"https:\/\/cybersecuritynews.com\/critical-elementor-plugin-vulnerability-let-attackers-takeover-wordpress-site-admin-control\/\" target=\"_blank\" rel=\"noreferrer noopener\">WordPress<\/a> login credentials for this site\u2019s administrator were previously stolen by infostealer malware. <\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"286\" src=\"https:\/\/i0.wp.com\/cybersecuritynews.com\/wp-content\/uploads\/2026\/01\/image-11-1024x286.png?resize=1024%2C286&#038;ssl=1\" alt=\"The domain wo.cementah.com hosting a ClickFix campaign\" class=\"wp-image-138562\" srcset=\"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/01\/image-11-1024x286.png 1024w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/01\/image-11-300x84.png 300w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/01\/image-11-768x215.png 768w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/01\/image-11-696x195.png 696w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/01\/image-11-1068x299.png 1068w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/01\/image-11-150x42.png 150w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/01\/image-11.png 1094w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\"><figcaption class=\"wp-element-caption\"><em>The domain wo.cementah.com hosting a ClickFix campaign<\/em><\/figcaption><\/figure>\n<p>Attackers used these valid credentials to access the website and upload malicious scripts, transforming a legitimate business site into an attack platform.<\/p>\n<p>Similar evidence exists for numerous other domains, including wo.cementah.com, where administrative credentials harvested by infostealers enabled unauthorized access for malware hosting.<\/p>\n<p>This feedback loop creates exponential growth in attack infrastructure. As more computers get infected, more credentials are stolen. <\/p>\n<p>More stolen credentials lead to more compromised websites, which expand the surface area for <a href=\"https:\/\/cybersecuritynews.com\/state-sponsored-hackers-now-widely-using-clickfix-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">ClickFix campaigns<\/a>, resulting in additional infections. The cycle becomes self-sustaining.<\/p>\n<p>The decentralized nature of this infrastructure makes disruption extremely difficult. Rather than operating from dedicated malicious servers, attackers hide within thousands of legitimate hosting providers using compromised business websites. <\/p>\n<p>Even if authorities dismantle major botnets, the distributed infrastructure remains largely intact.<\/p>\n<p>The ClickFix Hunter platform, developed by ReliaQuest researcher Carson Williams and integrated with Hudson Rock intelligence, provides critical visibility into this threat. <\/p>\n<p>According to <a href=\"https:\/\/www.infostealers.com\/article\/from-victim-to-vector-how-infostealers-turn-legitimate-businesses-into-malware-hosts\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Infostealers<\/a>, the tool distinguishes between purely malicious domains and compromised legitimate sites, enabling more effective remediation strategies.<\/p>\n<p>The cybersecurity community must recognize that modern malware distribution increasingly relies on exploiting human behavior rather than technical vulnerabilities. <\/p>\n<p>As browsers and operating systems become more secure, attackers pivot to social engineering tactics that trick users into turning off their own protections. <\/p>\n<p>Understanding and disrupting the infrastructure supporting these campaigns, particularly the credential theft feedback loop, is essential for breaking this dangerous cycle.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/infostealers-to-hijack-legitimate-business-infrastructure\/\">Infostealers Enable Attackers to Hijack Legitimate Business Infrastructure for Malware Hosting<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Dhivya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/infostealers-to-hijack-legitimate-business-infrastructure\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Infostealers Enable Attackers to Hijack Legitimate Business Infrastructure for Malware Hosting A dangerous cybercrime feedback loop has emerged where stolen credentials from infostealer malware enable attackers to hijack legitimate business websites and turn them into malware distribution platforms. Recent research by the Hudson Rock Threat Intelligence Team reveals this self-sustaining cycle transforms victims into unwitting [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,258,131],"tags":[130],"class_list":["post-9644","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-malware","category-vulnerability","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9644"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9644"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9644\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9644"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9644"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9644"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}