CARDS
CARDS
Multiple operations compromise legitimate WordPress sites and use fake CAPTCHA or Cloudflare-style verification prompts to persuade Windows users to copy and run attacker-supplied commands. The website is the delivery point; the visitor endpoint becomes the execution and credential-theft target.
Last updated Jul 18, 2026, 2:45 PM EDT
Actor Mapping
Targeting
Tradecraft
Tools / Observables
Source Reconciliation
Campaign rows are retained as source-backed context. Actor mappings do not automatically merge actor records; SOCRadar, MITRE, Mandiant, CrowdStrike, Microsoft, and other future sources can disagree on boundaries, aliases, or campaign ownership.
ClickFix is a technique, not one actor or malware family. IClickFix and ErrTraffic are framework labels; KongTuke is a source-named cluster. A named compromised website is not proof that every visitor executed malware, and no single CVE explains the ecosystem.
Evidence Controls
IntelliOS
Citations