Threat actors used compromised legitimate websites—especially WordPress sites—to display fake CAPTCHA or browser-verification prompts that trick visitors into manually running malicious commands, resulting in information-stealer infections. Kroll reported that the CLEARFAKE campaign evolved from fake browser updates to a ClickFix-style technique in which victims copy, paste, and execute malicious PowerShell, while CyberCX linked a similar DarkEngine operation to at least 2,353 likely compromised WordPress sites after attackers allegedly stole administrator credentials through SEO-poisoned phishing pages and fake WP Engine logins.
The campaigns relied on injected JavaScript and increasingly evasive delivery methods, including EtherHiding, which retrieves attacker-controlled code from the BNB Smart Chain through blockchain-related endpoints. Observed payloads decoded obfuscated content, downloaded follow-on malware, and performed discovery and credential theft, while NJCCIC said related ClickFix activity installed MonsterV2 and could also deliver StealC or Rhadamanthys. Stolen data included browser information, account credentials, cryptocurrency wallets, and other sensitive personal information, showing how fake verification prompts on trusted sites are being used as an effective malware-delivery channel.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Kroll observed a new CLEARFAKE technique in May 2024 that redirected victims to a fake error page and instructed them to copy, paste, and run malicious PowerShell from the Start Menu. The payload then flushed DNS, cleared the clipboard, and retrieved or downloaded additional malware components.
Kroll reported that CLEARFAKE, which originally targeted Windows users, expanded to macOS users in Q4 2023. The campaign continued using fake browser update prompts on compromised websites.
Kroll said the CLEARFAKE fake browser update campaign was initially identified in Q2 2023. The campaign used malicious JavaScript on compromised webpages to present fake browser update lures to Windows users.
NJCCIC reported a new iteration of the ClickFix phishing technique in which emails led victims to compromised legitimate websites displaying fake CAPTCHA overlays. If users followed the instructions, the MonsterV2 infostealer was downloaded and installed, with similar campaigns also capable of delivering StealC or Rhadamanthys.
CyberCX warned of a financially motivated campaign called DarkEngine that embedded fraudulent CAPTCHA prompts into compromised WordPress websites to infect visitors with malware such as information stealers and remote access tools. It also said it had been contacting affected organisations and advised administrators to review account activity and inspect sites for malicious injections.
CyberCX said it identified at least 2,353 likely compromised websites in the DarkEngine campaign, including 82 belonging to organisations in Australia and New Zealand. The campaign used SEO poisoning and fake WP Engine login pages to steal administrator credentials and inject fake CAPTCHA prompts into legitimate WordPress sites.
4 references tracked. Mallory keeps watching after this page renders.
prophetsecurity.ai
Open sourcecyber.nj.gov
Open sourcesecuritybrief.com.au
Open sourcekroll.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.