Categories: Cyber Security News

Cybersecurity Alert – Fake BBC News and Fraudulent Cloudflare Verification Exploit in Latest ClickFix Attack

Cybersecurity researchers have identified a sophisticated new threat campaign that weaponizes trusted news sources and security verification systems to deliver malware.

The latest ClickFix attack variant combines convincing BBC news impersonation with fake Cloudflare verification screens, contributing to a staggering 517% surge in ClickFix attacks during the first half of 2025, according to ESET’s Threat Report.

Sponsored
class="wp-block-heading" id="attack-methodology-and-technical-execution">Attack Methodology and Technical Execution

The campaign begins when victims click on deceptive online advertisements or search results, redirecting them to pixel-perfect replicas of BBC news websites populated with stolen legitimate articles.

These fake sites serve as delivery mechanisms for the primary attack vector: fraudulent Cloudflare verification pages.

Clickfix attack

The fake verification screens replicate authentic Cloudflare Turnstile challenges with genuine logos and Ray ID footers. When users attempt to complete the “Verify you are human” checkbox, they receive instructions to execute what appears to be a routine verification process.

The attack instructs users to press Windows + R to open the Run dialog, followed by Ctrl + V to paste a “verification command,” and Enter to execute it.

Unknown to victims, clicking the verification button pre-loads malicious PowerShell commands into their system clipboard. The executed commands download and install various malware families, including Lumma Stealer, DarkGate, AsyncRAT, and NetSupport.

These malicious payloads often retrieve Base64-encoded code from legitimate-seeming services and include anti-analysis features that terminate execution in virtual machine environments, achieving zero detection across many antivirus platforms.

Evolving Tactics and Advanced Evasion

Security researcher mr d0x recently identified a variant called FileFix that adapts the technique by leveraging Windows File Explorer instead of the Run dialog, instructing users to paste malicious commands into the address bar.

This evolution demonstrates threat actors’ continuous adaptation to maintain effectiveness as security awareness increases.

Sponsored

The fake Cloudflare pages incorporate authentic marketing text copied directly from Cloudflare’s official website, making detection extremely challenging.

Some variants display fake progress indicators and success messages to convince users further they’re completing legitimate security processes.

Clickfix attack

Defense Strategies

Security experts recommend several mitigation strategies: disabling the Windows Run dialog through Group Policy modifications, implementing behavioral monitoring for unusual PowerShell activity, and training users to recognize that legitimate services like Cloudflare never require direct operating system interaction for verification.

Microsoft tracks these campaigns under threat actor designations like Storm-1865, while security firms have developed specialized detection rules targeting ClickFix attacks.

This campaign represents a concerning escalation in social engineering sophistication, exploiting user psychology rather than technical vulnerabilities to bypass traditional security measures.

Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates

The post Cybersecurity Alert – Fake BBC News and Fraudulent Cloudflare Verification Exploit in Latest ClickFix Attack appeared first on Cyber Security News.

rssfeeds-admin

Recent Posts

Amazon Prime Video’s ad-free plan is getting a price hike

Amazon Prime Video is raising the price of its ad-free plan in the US and…

19 minutes ago

The Big 12 basketball tournament is ditching slippery LED courts for hardwood

They may be great for fan engagement and selling ads, but the Big 12 has…

19 minutes ago

Donkey Kong Bananza Developers on Voxels, Sandboxes, and a Delicious Bacon Burger Prototype

Donkey Kong Bananza is a game that emerged from constant experimentation with tons of different…

28 minutes ago

The Best Change in Netflix’s One Piece Shows Why Luffy Is Not as Dumb as You Think

There are two things you can always count on Monkey D. Luffy to do: eat…

28 minutes ago

Euphoria Composer Labrinth Claims He’s ‘Done’ With the Industry and the Show Ahead of Season 3

Euphoria Season 3 has been riddled with delays and problems for the approximately four long…

28 minutes ago

The R2 is nearly here — can Rivian stick the landing?

On Thursday, Rivian revealed its most important vehicle to date: the R2, a midsize SUV…

1 hour ago

This website uses cookies.