PULSE NAME
ClickFix-as-a-Service platform with fake Cloudflare CAPTCHA using compromised WordPress sites using a DOM overlay
WHITE dispensight 2026-05-20 Modified: 2026-05-20
105
IOCs
HIGH VOLUME
TLP:GREEN | SL-ADV-2026-WP-001 UNIFIED March 20 – May 19, 2026 ClickFix/TDS cluster active since March 2026. Compromised WordPress sites inject an obfuscated JS loader that fires a synchronous XHR to a TDS C2 (ntdnewtds.shop / dnsnewtds.shop / sdntds.shop), fetches a remote payload, and executes it inline. Victims see a fake Cloudflare CAPTCHA (Shadow DOM, 50-language localized) that silently writes a PowerShell command to clipboard. PS chain: IRM stage1 → IWR stage2 → csc.exe compiles Rozena DLL → svchost injection → DonutLoader C2 (158.94.208.104) → browser/Firefox/crypto wallet credential theft → self-delete. Parallel Python chain (Protected.py) uses direct NT syscalls for EDR bypass. Per-campaign C2 IPs, segmented DonutLoader payloads (my_ / student_), and a 6-domain TDS pool suggest a ClickFix-as-a-Service affiliate platform. 4 JS variants documented March–May 2026. SecureLeaf · Dispensight Security Research · SL-ADV-2026-WP-001 rev. 3.0 STIX 2.1 · 438 objects · 4 variants · 2 execution chains
Indicators of Compromise (9 / 105 total)
All CIDR FileHash-MD5 FileHash-SHA1 FileHash-SHA256 IPv4 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 09d8e272484c2bef81590887460981ff 2026-05-20
FileHash-MD5 25e90438c448898c2b8fa0814ccbd0c8 2026-05-20
FileHash-MD5 4f67ea9205c3ca7c9e04582d3b9bdd1d MD5 of 4b77eae349a8cbcea7133cf3640a64ebf1f69d54d8f6469d7be6fdc188ca4ca4 2026-05-20
FileHash-MD5 51b46342163ef37f5f41c269ffb337d3 MD5 of 724a8445c5c3fd57778d82f62b9d4a6112a3bb2d 2026-05-20
FileHash-MD5 7c268bfab0653cdca45b4dc3c1ee0092 MD5 of f1542a7697e04865e1dfeeed084e5ea5870100f0 2026-05-20
FileHash-MD5 c43c4bfd2e1a44ef690e6801be2b4099 2026-05-20
FileHash-MD5 c67211d946c6762bbef2afdb74c63416 2026-05-20
FileHash-MD5 f29926ae72794dde60ae1d57d97c5781 2026-05-20
FileHash-MD5 ff1d1a915f7a4a1df4a16e0dd2990241 2026-05-20