← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
ClickFix-as-a-Service platform with fake Cloudflare CAPTCHA using compromised WordPress sites using a DOM overlay
TLP:GREEN | SL-ADV-2026-WP-001 UNIFIED March 20 – May 19, 2026
ClickFix/TDS cluster active since March 2026. Compromised WordPress sites inject an obfuscated JS loader that fires a synchronous XHR to a TDS C2 (ntdnewtds.shop / dnsnewtds.shop / sdntds.shop), fetches a remote payload, and executes it inline. Victims see a fake Cloudflare CAPTCHA (Shadow DOM, 50-language localized) that silently writes a PowerShell command to clipboard. PS chain: IRM stage1 → IWR stage2 → csc.exe compiles Rozena DLL → svchost injection → DonutLoader C2 (158.94.208.104) → browser/Firefox/crypto wallet credential theft → self-delete. Parallel Python chain (Protected.py) uses direct NT syscalls for EDR bypass. Per-campaign C2 IPs, segmented DonutLoader payloads (my_ / student_), and a 6-domain TDS pool suggest a ClickFix-as-a-Service affiliate platform. 4 JS variants documented March–May 2026.
SecureLeaf · Dispensight Security Research · SL-ADV-2026-WP-001 rev. 3.0
STIX 2.1 · 438 objects · 4 variants · 2 execution chains
MITRE ATT&CK & Malware Families
Indicators of Compromise (9 / 105 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | 09d8e272484c2bef81590887460981ff | — | 2026-05-20 | |
| FileHash-MD5 | 25e90438c448898c2b8fa0814ccbd0c8 | — | 2026-05-20 | |
| FileHash-MD5 | 4f67ea9205c3ca7c9e04582d3b9bdd1d | MD5 of 4b77eae349a8cbcea7133cf3640a64ebf1f69d54d8f6469d7be6fdc188ca4ca4 | 2026-05-20 | |
| FileHash-MD5 | 51b46342163ef37f5f41c269ffb337d3 | MD5 of 724a8445c5c3fd57778d82f62b9d4a6112a3bb2d | 2026-05-20 | |
| FileHash-MD5 | 7c268bfab0653cdca45b4dc3c1ee0092 | MD5 of f1542a7697e04865e1dfeeed084e5ea5870100f0 | 2026-05-20 | |
| FileHash-MD5 | c43c4bfd2e1a44ef690e6801be2b4099 | — | 2026-05-20 | |
| FileHash-MD5 | c67211d946c6762bbef2afdb74c63416 | — | 2026-05-20 | |
| FileHash-MD5 | f29926ae72794dde60ae1d57d97c5781 | — | 2026-05-20 | |
| FileHash-MD5 | ff1d1a915f7a4a1df4a16e0dd2990241 | — | 2026-05-20 |
References (2)