Fake captchas on 2,000 hacked WordPress sites push malware

Check Point links nearly 2,000 hacked WordPress sites to fake-captcha malware delivery.

CSBadmin
2 Min Read

Fake CAPTCHA prompts on roughly 2,000 hacked WordPress sites are delivering malware, Check Point researchers report. The campaign, named StopAndProtect, overlays legitimate pages with a phony verification step for non-Windows visitors.

Each compromised site runs a malicious “verify” plugin. After the attacker uploads a file called activator.php the overlay activates, then the plugin deletes itself. Visitors who follow the prompt copy and run a command, opening the way for malware delivery, credential theft, and surveillance.

A custom automation tool lets the botnet operator mass-manage the infected pages, Check Point says. Secure upload and delete PHP scripts move additional files, toggle the fake-captcha ClickFix on and off, and control caching across the fleet.

By July 24, more than 6,000 unique IP addresses had been compromised, led by the US at 1,852, with Russia and India at 630 each.

Eli Smadja of Check Point described the abuse as thousands of poorly maintained WordPress sites turned into distributed criminal infrastructure for malware delivery, surveillance, data theft, and ransomware.

The operation is another spin on ClickFix social engineering, where victims are told to paste a command into a terminal and unknowingly run attacker code. Earlier this month Microsoft documented more than 250 front-end domains hiding macOS malware lures behind the same trick with browser fingerprinting.

Anyone hit with an unexpected CAPTCHA demanding copied commands should close the tab, keep software current, and leave sites that push unusual steps outside the browser.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.