HomeSecurityClickFix techniques used in new infostealer campaigns

ClickFix techniques used in new infostealer campaigns

Cybercriminals are combining compromised websites with increasingly sophisticated ClickFix techniques to distribute infostealer malware. One campaign alone has already targeted more than 250 WordPress sites in 12 countries.

ClickFix infostealer

The malicious campaign leads to hidden loading of payloads into memory, while a separate attack, detected by Microsoft, targets the Windows Terminal to execute the payloads (instead of the traditional Run dialog).

According to researchers at Rapid7, the WordPress campaign has been active since December 2025 and targets visitors with fake Cloudflare CAPTCHA challenges. The compromised WordPress sites include regional news outlets, local business websites, and even the official website of a U.S. Senate candidate.

WordPress Hacking and ClickFix Techniques: Methods to Avoid Detection

The ClickFix campaign, which targets WordPress, distributes three separate infostealer payloads — two of them previously unknown — and uses domain infrastructure that appears to have been created since July 2025.

See also: Storm-2561 targets corporate VPN users through SEO poisoning

Attackers disguise the embedded JavaScript snippet as a performance optimizer that is only triggered if the visitor's browser does not have a WordPress admin cookie. This technique aims to hide the malicious behavior from website administrators.

The script retrieves a fake Cloudflare CAPTCHA verification challenge from one of 14 domains controlled by the attackers. The fake CAPTCHA instructs visitors to copy and paste a command into the Windows Run dialog. The malicious command consists of encoded JavaScript and PowerShell code that launches a shellcode loader in memory, named DoubleDonut Loader.

ClickFix techniques used in new infostealer campaigns

The loader injects payloads directly into legitimate Windows processes and uses reflected code loading.

“The malware chain runs almost entirely in memory and within inconspicuous Windows processes, rendering traditional file-based detection ineffective,” Rapid7 wrote. The compromised sites did not share the same vulnerable WordPress version or plugin, indicating that the attackers may be exploiting weak credentials or using exploits for multiple vulnerabilities.

New payloads

DoubleDonut Loader distributes a new variant of Vidar Stealer, a known infostealer, that uses a dead drop resolver to recover command and control configuration and dynamic API resolution.

See also: Operation Synergia III: INTERPOL dismantles digital criminal networks

In addition to Vidar, two previously unknown infostealers have been observed, one written in .NET and one in C++. Rapid7 has named these new programs Impure Stealer and VodkaStealer. Both use detection evasion techniques, including non-standard data encoding and symmetric encryption for command-and-control communications or sandbox environment detection.

ClickFix techniques are constantly evolving

In addition to new payloads, attackers are also evolving their ClickFix traps.

A separate campaign detected by Microsoft's Threat Intelligence team replaced the usual Windows Run dialog (Win+R) with the Windows Terminal application (Win+X) for executing commands . This campaign distributed the well-known Lumma Stealer and the NetSupport RAT . A second payload included a VBScript chain , executed via MSBuild, and used a technique known as etherhiding to download credential-harvesting code.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

ClickFix techniques used in new infostealer campaigns

Security firm ESET estimated that ClickFix attacks increased by 517% last year , with multiple variants dubbed CrashFix, ConsentFix, and PhantomCaptcha . Each uses different traps and distribution mechanisms. This basic social engineering tactic has proven so effective that even state-sponsored hacking groups , such as Lazarus North Korea’s Group , MuddyWater Iran’s , and APT28 Russia’s , have adopted it.

See also: Hive0163 uses AI malware Slopoly in ransomware attacks

In January, researchers from Sekoia reported that a separate ClickFix framework, dubbed IClickFix, had been embedded in over 3,800 WordPress sites as of 2024. WordPress site administrators should ensure that admin login panels are not publicly exposed, as Rapid7 noted that almost all of the compromised sites had accessible admin pages.

Rapid7 has published breach indicators and YARA detection rules on its public GitHub repository.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS