
Fake CAPTCHA “Copy/Paste” Sites Push CastleLoader
Threat actors are using fake CAPTCHA pages on compromised or lookalike websites to trick people into copying and pasting malicious commands (“paste and run”).…
Attackers compromised hundreds of legitimate websites and injected code that sent visitors to a fake Cloudflare page. The fake page used a “ClickFix” trick to convince users to run steps that installed malware. The incident shows how criminals can use trusted brands and trusted sites as the delivery mechanism, not just as a reputational issue.
Attackers compromised legitimate, trusted websites and injected code that redirected visitors to a fake Cloudflare verification page. Rather than a normal CAPTCHA, the page walked users through steps framed as a browser "fix" or security check. Following those steps resulted in malware being installed on the visitor's device, a technique known as ClickFix. Researchers found the same injected code running across hundreds of unrelated sites, all feeding shared attacker infrastructure, which suggests a coordinated campaign rather than isolated incidents.
The campaign worked because it exploited trust in two layers at once: trust in the compromised website itself, and trust in Cloudflare as a security brand that many users already associate with legitimate verification prompts. Visitors were not clicking a suspicious link in an email, they were visiting sites they already trusted, including institutions like Harvard, Oxford, and DuckDuckGo. That combination made the fake verification step feel like a routine part of browsing rather than an attack.
Organizations and individuals should treat any prompt asking them to "fix" or manually resolve a browser issue as a red flag, regardless of how legitimate the branding looks. Employees, students, faculty, and customers should be reminded that trusted brands and trusted sites can be used against them, since attackers in this case are described as posing as something users already trust. Security teams should also recognize that blocking a single malicious URL inside the corporate perimeter does not remove the underlying infrastructure; the article notes this can lead to a whack-a-mole cycle where blocked links simply reappear elsewhere. Reporting suspicious pages and supporting broader takedown efforts is more effective than local blocking alone. Given that this incident spans education, online platforms, retail, and financial services, awareness training should extend beyond IT and security staff to include marketing, brand, and legal teams who may be first to notice brand impersonation affecting their own organization's web presence.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
It is a technique where a fake Cloudflare verification page tricks visitors into manually running steps that install malware on their device.
Researchers found that attackers poisoned more than 700 websites, including sites run by Harvard, Oxford, and DuckDuckGo.
No. Blocking a phishing URL internally only stops it from resolving inside your own perimeter, but the broader attacker infrastructure remains active and can resurface elsewhere.
It shows that trusted brands and trusted websites can be turned into delivery mechanisms for malware, meaning trust alone is not a reliable safety signal for users.
You land on Harvard’s website, and suddenly a Cloudflare ‘Security Check’ pops up, telling you to fix your browser. Researchers found more than 700 poisoned sites, even Harvard, Oxford, and DuckDuckGo, showing this fake Cloudflare page that walks you through a ‘ClickFix’ step to silently install malware. Here’s the trick: real Cloudflare checks are just quick loading or a CAPTCHA. If a ‘Cloudflare’ page tells you to download, run commands, or change settings on your computer, that’s not protection, that’s the attack. If any ‘Cloudflare’ page on a website asks you to run steps on your device, stop immediately and report it to security, don’t click through a ClickFix into malware.

Threat actors are using fake CAPTCHA pages on compromised or lookalike websites to trick people into copying and pasting malicious commands (“paste and run”).…

Ukraine’s CERT says the Russia-linked Sandworm group is tricking targets into infecting their own PCs using compromised websites that display fake CAPTCHA…

A state-sponsored campaign in South Korea used spear-phishing and hacked “trusted” local websites to infect visitors who had vulnerable AnySign4PC installed.…

Microsoft observed real-world campaigns where victims were tricked by “ClickFix” prompts into pasting a command into Windows Run, which then installed ACR…

Researchers report a real, active malware operation where compromised websites use “ClickFix” style prompts to trick people into manually pasting and running…

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…