NCSC alerts to ClickFix attacks exploiting fake verification pages

A website can appear completely clean to security tools yet serve malware to every real visitor
ClickFix attacks hide malicious content from automated scanners while displaying it only to human browsers.
Mark

So these attackers are essentially spoofing Cloudflare's verification system. How do they even get that level of access to a website in the first place?

Mimi

The source doesn't detail the initial compromise vector—it focuses on what happens after attackers are already inside. But once they have access, they can inject code that displays these fake screens to visitors.

Luke

That's an important gap. We know WordPress sites are targeted, but we don't know if that's because WordPress is inherently more vulnerable or because it's simply more common. The warning doesn't distinguish between those two things.

Mark

And the malware that gets installed—what exactly does it do beyond stealing information?

Mimi

The NCSC describes it as software designed to steal information, but the warning doesn't specify what kind of information or how the theft occurs. It's a broad category.

Luke

Right. We know the commands install malware, and we know the goal is data theft, but the mechanics of the actual theft aren't explained. That matters for understanding the real risk.

Mark

Why is it so hard for security scanners to detect this? Is it just because the attackers are clever, or is there something structural about how these tools work?

Mimi

The attackers deliberately hide the malicious content from automated systems while showing it to real browsers. They're exploiting the difference between how a bot sees a website and how a human sees it.

Luke

Which means the vulnerability isn't really in the website itself—it's in the gap between what automated tools can see and what actual users experience. That's a fundamental problem for any security strategy that relies only on scanning.

Mark

So what's the actual risk to someone who visits one of these compromised sites?

Mimi

If you see what looks like a normal verification prompt and follow the instructions to run a command, you're executing malware on your own machine. The attacker doesn't need to break in—you let them in.

Luke

Though we should note that most users probably wouldn't recognize the difference between a legitimate prompt and a fake one. The NCSC is essentially asking people to be suspicious of something that's designed to look trustworthy.

  • Criminals are hijacking trusted websites and weaponising the very security rituals — CAPTCHAs, browser prompts — that users have been trained to obey without question.
  • The attack is nearly invisible to automated scanners, meaning a site can pass every security check while actively delivering malware to real visitors in real time.
  • WordPress sites are frequent targets, but the threat extends across platforms, and simply removing the fake prompt does nothing if the underlying access point remains open.
  • Attackers often leave multiple backdoors, allowing them to reinfect a cleaned site within days — turning remediation into a cycle rather than a resolution.
  • The NCSC is urging website owners to test their own sites manually — across different browsers, IP addresses, and devices — because only a human visitor will see what the attack is designed to show.

New Zealand's National Cyber Security Centre has raised an alarm about ClickFix, a quietly spreading deception in which legitimate websites are turned against their own visitors — displaying familiar-looking verification screens that coax ordinary people into running commands that compromise their own machines. What makes this threat philosophically unsettling is its inversion of trust: the more a user recognises and follows routine digital cues, the more vulnerable they become. Automated defences see nothing wrong, while every human who arrives is potentially harmed — a reminder that in the digital age, the appearance of safety can be engineered as precisely as safety itself.

New Zealand's National Cyber Security Centre has issued a warning about a deceptive attack method called ClickFix, in which criminals compromise legitimate websites and inject fake verification screens to trick visitors into infecting their own machines. The scheme mimics the familiar Cloudflare "Verify You Are Human" prompt — but instead of a simple click, visitors are instructed to run commands on their computer, commands that execute malware capable of stealing sensitive information.

What makes ClickFix especially dangerous is its deliberate invisibility to automated tools. Malicious content is hidden from security scanners and search engine crawlers, appearing only to real people using standard browsers. A website can scan as completely clean while serving malware to every genuine visitor — an asymmetry that allows attacks to persist undetected for weeks.

WordPress sites are frequently targeted, though no platform is immune. The NCSC stresses that removing the fake prompt is not enough: attackers typically leave multiple backdoors behind, enabling reinfection within days. Organisations must investigate how the compromise occurred and close those entry points entirely.

Beyond fake CAPTCHA screens, ClickFix variants include fraudulent browser update prompts, full-screen overlays, and injected JavaScript that silently copies malicious commands to a visitor's clipboard — all invisible to crawlers, all visible to anyone browsing normally.

Detecting these attacks demands hands-on testing: visiting the site in standard and incognito browsers, from different IP addresses, and across mobile and desktop devices. Because attackers tailor what they serve based on visitor characteristics, only varied human testing can reveal what automated scans will miss. The broader lesson is stark — a site that passes every security check may still be actively harming the people it is meant to serve.

New Zealand's National Cyber Security Centre has issued a warning about a deceptive attack method called ClickFix, in which criminals compromise legitimate websites and inject fake verification screens designed to trick visitors into infecting their own machines. The scheme works by displaying what appears to be a standard Cloudflare "Verify You Are Human" prompt or CAPTCHA—the kind of security check most internet users encounter regularly. But instead of simply clicking a box to prove they are human, visitors are instructed to run commands on their computer. Those commands execute malware capable of stealing sensitive information.

What makes ClickFix particularly dangerous is its invisibility to the tools that normally catch such threats. The malicious content is deliberately hidden from security scanners and search engine crawlers, visible only to actual people using standard web browsers. A website can appear completely clean when scanned by automated systems, yet serve malware to every real visitor who lands on it. This asymmetry—safe to machines, dangerous to humans—is what allows the attacks to persist undetected for extended periods.

WordPress sites have become a common target, though the vulnerability is not limited to any single platform. The NCSC emphasizes that website owners cannot simply remove the fake prompt and consider the problem solved. Attackers who have gained access to a site often leave behind multiple entry points, allowing them to reinfect it repeatedly. Organisations must investigate how the compromise occurred in the first place and close those gaps, or they will find themselves dealing with the same attack again within days or weeks.

The warning includes a list of signs that a website has been hit by ClickFix. Beyond the obvious fake Cloudflare screens, attackers often deploy fraudulent browser update prompts or full-screen overlays that appear immediately after a page loads. Some variants inject malicious JavaScript that copies PowerShell, Terminal, or shell commands directly to a visitor's clipboard—a technique that makes it easier for users to accidentally paste and execute dangerous code. The common thread is that all of this activity remains invisible to automated crawlers and security tools while being fully visible to anyone browsing the site normally.

Detecting these attacks requires a deliberate, multi-layered testing approach. The NCSC recommends that organisations test their websites using a standard browser session, then again in incognito or private browsing mode. Testing from different IP addresses and across both mobile and desktop devices can reveal inconsistencies in how the site behaves. Because attackers often serve different content based on the characteristics of the visitor—real browser versus bot, known IP versus unknown—this variation in testing methods is essential to catching what automated scans will miss.

The broader implication is that website security can no longer rely solely on automated tools. A site that passes all its security checks may still be actively harming visitors. Website owners and security teams must adopt a more hands-on approach, regularly visiting their own sites as ordinary users would, watching for unusual prompts or overlays, and remaining alert to the possibility that what looks legitimate might be carefully crafted deception.

Website owners cannot simply remove the fake prompt and consider the problem solved; attackers often leave multiple entry points for reinfection
— New Zealand National Cyber Security Centre
Quieres la nota completa? Lee el original en Reseller News ↗
Contáctanos FAQ