CARDS
CARDS
Multiple operations compromise legitimate WordPress sites and use fake CAPTCHA or Cloudflare-style verification prompts to persuade Windows users to copy and run attacker-supplied commands. The website is the delivery point; the visitor endpoint becomes the execution and credential-theft target.
Last updated Jul 18, 2026, 2:45 PM EDT
Evidence Boundary
Bottom Line Up Front
Multiple operations compromise legitimate WordPress sites and use fake CAPTCHA or Cloudflare-style verification prompts to persuade Windows users to copy and run attacker-supplied commands. The website is the delivery point; the visitor endpoint becomes the execution and credential-theft target.[1][2][3][4]
Compromised sites can distribute stealers or remote-access tooling to visitors, creating separate website-remediation, endpoint-containment, credential-rotation, privacy, and downstream-account risks.[1][2][3][4]
Run two parallel workstreams: preserve and eradicate unauthorized WordPress code, accounts, and persistence; and isolate any endpoint where a user ran the prompt, preserve the exact command, rotate reachable credentials and sessions, and hunt for loader, stealer, or remote-access activity.[1][2][3][4]
Decision Summary
Multiple operations compromise legitimate WordPress sites and use fake CAPTCHA or Cloudflare-style verification prompts to persuade Windows users to copy and run attacker-supplied commands. The website is the delivery point; the visitor endpoint becomes the execution and credential-theft target.
The retained record scopes this as compromised website delivery / social engineering / infostealer distribution activity during Late 2024 through 2026 reporting window. Compromised sites can distribute stealers or remote-access tooling to visitors, creating separate website-remediation, endpoint-containment, credential-rotation, privacy, and downstream-account risks.[1][2][3][4]
Run two parallel workstreams: preserve and eradicate unauthorized WordPress code, accounts, and persistence; and isolate any endpoint where a user ran the prompt, preserve the exact command, rotate reachable credentials and sessions, and hunt for loader, stealer, or remote-access activity.[1][2][3][4]
Confirmed reporting is separated from attribution, victim, and prevalence claims that the retained sources do not establish. Confidence: High for the recurring technique and compromised-WordPress delivery pattern; source-specific for framework, cluster, payload, scale, and actor attribution..[1][2][3][4]
Actor Mapping
Targeting
Tradecraft
Tools / Observables
Source Reconciliation
Campaign rows are retained as source-backed context. Actor mappings do not automatically merge actor records; SOCRadar, MITRE, Mandiant, CrowdStrike, Microsoft, and other future sources can disagree on boundaries, aliases, or campaign ownership.
ClickFix is a technique, not one actor or malware family. IClickFix and ErrTraffic are framework labels; KongTuke is a source-named cluster. A named compromised website is not proof that every visitor executed malware, and no single CVE explains the ecosystem.
Evidence Controls
IntelliOS
Citations