Friday, 4 July, 2025
Hackers Deploy Fake Cloudflare "Verification" to Push Malware via Clipboard Hijack

Cybercriminals are using realistic fake Cloudflare CAPTCHA screens (“ClickFix”) to trick users into executing hidden PowerShell commands. Once users click “Verify,” a malicious script injects code into the clipboard and prompts them to paste it using Windows Run, triggering sophisticated malware downloads—like info‑stealers and RATs—that evade traditional antivirus. This rising threat highlights an advanced social‑engineering tactic exploiting security fatigue and living‑off‑the‑land binaries
Read full story at Cybersecurity News