HomeSecurityHackers use fake Cloudflare verification screen

Hackers use fake Cloudflare verification screen

A sophisticated social engineering campaign has emerged, targeting unsuspecting users via fake Cloudflare verification screens, marking a new phase in malware distribution tactics.

See also: Cloudflare: Blocks AI data crawlers by default

This attack method exploits the trusted image of legitimate online security to trick victims into executing malicious code on their systems, relying on the inherent trust users have in established security providers.

Cloudflare verification

This malicious campaign uses a multi-layered attack strategy, starting with a convincing fake CAPTCHAdesigned to mimic Cloudflare's authentic security checks. When users encounter this deceptive interface, they are prompted to complete a seemingly routine verification process, unwittingly triggering a complex malware installation sequence.

See also: Cloudflare Tunnels abused in new malware campaign

Security researchers, including analysts like Shaquib Izhar, have characterized this campaign as particularly dangerous due to its sophisticated approach to social engineering and advanced detection evasion.

The attack demonstrates how cybercriminals are increasingly exploiting users' familiarity with legitimate security mechanisms, bypassing traditional security awareness training and infiltrating networks.

Hackers use fake Cloudflare verification screen
Hackers use fake Cloudflare verification screen

Upon selecting the “Verify” button, the malicious website injects PowerShell code directly into the user’s clipboard, while also recording their IP address for identification purposes. The system then prompts victims to perform another verification step, creating a false sense of legitimacy, while in reality monitoring their actions through keystroke logging capabilities.

See also: Cloudflare blocks 7.3 Tbps DDoS attack

This type of attack highlights a worrying trend in cybersecurity :threats are no longer based solely on technical vulnerabilities, but are also exploiting human behavior as a primary means of infiltration. Users' trust in well-known services, such as Cloudflare, is being turned into a weapon in the hands of sophisticated attackers, who use realistic interfaces to mislead even unsuspecting users.

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS