Fake Cloudflare Pages Hijack Trusted Websites

Security Affairs · High sophistication
Last updated July 30, 2026

Attackers compromised hundreds of legitimate websites and injected code that sent visitors to a fake Cloudflare page. The fake page used a “ClickFix” trick to convince users to run steps that installed malware. The incident shows how criminals can use trusted brands and trusted sites as the delivery mechanism, not just as a reputational issue.

How the attack worked

Attackers compromised legitimate, trusted websites and injected code that redirected visitors to a fake Cloudflare verification page. Rather than a normal CAPTCHA, the page walked users through steps framed as a browser "fix" or security check. Following those steps resulted in malware being installed on the visitor's device, a technique known as ClickFix. Researchers found the same injected code running across hundreds of unrelated sites, all feeding shared attacker infrastructure, which suggests a coordinated campaign rather than isolated incidents.

Why it succeeded

The campaign worked because it exploited trust in two layers at once: trust in the compromised website itself, and trust in Cloudflare as a security brand that many users already associate with legitimate verification prompts. Visitors were not clicking a suspicious link in an email, they were visiting sites they already trusted, including institutions like Harvard, Oxford, and DuckDuckGo. That combination made the fake verification step feel like a routine part of browsing rather than an attack.

What to watch for

  • An unexpected "security check" or "verification" page appearing after visiting a normal, trusted website
  • Instructions that go beyond a simple checkbox or CAPTCHA, especially anything asking you to run commands or steps on your own device
  • A verification prompt that appears mid-browsing rather than during a login to internal company systems
  • Multiple unrelated sites showing the same unusual prompt, which can indicate shared attacker infrastructure behind the scenes

Building resistance

Organizations and individuals should treat any prompt asking them to "fix" or manually resolve a browser issue as a red flag, regardless of how legitimate the branding looks. Employees, students, faculty, and customers should be reminded that trusted brands and trusted sites can be used against them, since attackers in this case are described as posing as something users already trust. Security teams should also recognize that blocking a single malicious URL inside the corporate perimeter does not remove the underlying infrastructure; the article notes this can lead to a whack-a-mole cycle where blocked links simply reappear elsewhere. Reporting suspicious pages and supporting broader takedown efforts is more effective than local blocking alone. Given that this incident spans education, online platforms, retail, and financial services, awareness training should extend beyond IT and security staff to include marketing, brand, and legal teams who may be first to notice brand impersonation affecting their own organization's web presence.

Key findings

  • Attackers “poisoned more than 700 websites,” including Harvard, Oxford, and DuckDuckGo, to push victims into a malware-install flow.
  • Visitors were shown “a fake Cloudflare page” that attempted to trick them into running a “ClickFix” attack to install malware.
  • Researchers found “the same injected code running across hundreds of unrelated sites, all feeding shared attacker infrastructure.”
  • The article claims “two rival criminal groups were fighting each other for control of the same hijacked sites,” suggesting active, competitive exploitation.
  • The piece highlights that blocking individual phishing URLs internally doesn’t remove the underlying attacker infrastructure and can lead to “whack-a-mole.”

Who’s being targeted

  • Commonly targeted roles: All employees, Executive leadership, Marketing/Brand teams, Legal, SOC/Incident Response.
  • Affected industries: Education (universities), Online services / web platforms, Retail and ecommerce, Financial services.
  • Attack channels: website.
  • Impersonated: Cloudflare.

Red flags to watch for

  • A trusted site unexpectedly asks you to run steps on your computer to “verify” or “fix” access
  • A verification page appears to be Cloudflare but shows unusual instructions beyond a normal CAPTCHA
  • The prompt appears after visiting a legitimate organization’s website (not after logging into your company systems)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is the ClickFix attack seen on hijacked websites?

It is a technique where a fake Cloudflare verification page tricks visitors into manually running steps that install malware on their device.

How many websites were affected by this campaign?

Researchers found that attackers poisoned more than 700 websites, including sites run by Harvard, Oxford, and DuckDuckGo.

Is blocking the malicious URL enough to stop this threat?

No. Blocking a phishing URL internally only stops it from resolving inside your own perimeter, but the broader attacker infrastructure remains active and can resurface elsewhere.

Why does this attack matter even though it targets trusted brands?

It shows that trusted brands and trusted websites can be turned into delivery mechanisms for malware, meaning trust alone is not a reliable safety signal for users.

Read the video transcript

You land on Harvard’s website, and suddenly a Cloudflare ‘Security Check’ pops up, telling you to fix your browser. Researchers found more than 700 poisoned sites, even Harvard, Oxford, and DuckDuckGo, showing this fake Cloudflare page that walks you through a ‘ClickFix’ step to silently install malware. Here’s the trick: real Cloudflare checks are just quick loading or a CAPTCHA. If a ‘Cloudflare’ page tells you to download, run commands, or change settings on your computer, that’s not protection, that’s the attack. If any ‘Cloudflare’ page on a website asks you to run steps on your device, stop immediately and report it to security, don’t click through a ClickFix into malware.

Similar attacks

TerminalFix Fake CAPTCHA Tricks Users Into PowerShell

TerminalFix Fake CAPTCHA Tricks Users Into PowerShell

Microsoft reported a real-world campaign (“TerminalFix”) where attackers use compromised websites to show a fake Cloudflare CAPTCHA. The prompt tricks visitors into copying and running a malicious PowerShell/Terminal command, which then installs a reverse-tunnel backdoor that can give attackers…

August 30, 2026
Fake CAPTCHA “Copy/Paste” Sites Push CastleLoader

Fake CAPTCHA “Copy/Paste” Sites Push CastleLoader

Threat actors are using fake CAPTCHA pages on compromised or lookalike websites to trick people into copying and pasting malicious commands (“paste and run”). The article describes real campaigns tied to CastleLoader and similar activity, including fake background-removal sites and job-site…

July 23, 2026
Spy Groups Phish Victims Into Chrome Exploit Kit

Spy Groups Phish Victims Into Chrome Exploit Kit

Researchers reported four separate espionage groups using the same “BlueMoon” exploit kit within days, targeting organizations in the US and Southeast Asia. The attacks began with phishing emails that lured recipients to attacker-controlled websites, where Chrome and Windows vulnerabilities were…

September 10, 2026
Fake CAPTCHA ClickFix Drops Amatera via WebDAV

Fake CAPTCHA ClickFix Drops Amatera via WebDAV

Cisco Talos investigated a real infection chain seen at a Ukrainian government organization where a disguised DLL was executed directly from a WebDAV network path. Attackers used a compromised website to show a fake Google CAPTCHA-style “verification” prompt that tricks users into running a copied…

September 8, 2026
BengalSEO: Search Lures to Malware & Scam Calls

BengalSEO: Search Lures to Malware & Scam Calls

Investigators described a real, long-running SEO poisoning operation (“BengalSEO”) that manipulates search results to push victims to fake support and activation pages. The pages impersonate well-known consumer brands, then route visitors through redirects and CAPTCHA checks to either download…

September 1, 2026
Fake CAPTCHA ‘ClickFix’ Drops Cruciferra Malware

Fake CAPTCHA ‘ClickFix’ Drops Cruciferra Malware

A real malware campaign used compromised websites to show fake CAPTCHA/verification pages that tricked people into copying and running a PowerShell command themselves. That manual “copy/paste” step helped the attackers bypass normal download defenses and install the Cruciferra loader, which then…

August 25, 2026