Briefing

Australia warns of ClickFix attacks pushing Vidar Stealer malware

security
by Bill Toulas · WordPress Cloudflare

Patch WordPress themes, plugins, and remove unused components; restrict PowerShell execution and enable application allow‑listing to stop ClickFix attacks.

What to do now

Patch all WordPress themes and plugins to the latest versions, remove unused components, restrict PowerShell execution, enable application allow‑listing, and configure a web application firewall to block fake CAPTCHA prompts.

Summary

Australia’s Cyber Security Center (ACSC) has warned that a ClickFix social‑engineering campaign is actively targeting WordPress sites to deliver the Vidar Stealer malware.

The attack tricks users into executing a malicious PowerShell command after a fake Cloudflare verification or CAPTCHA prompt appears on compromised WordPress pages, which then installs Vidar. Vidar deletes its executable after launch, runs from memory, and obtains its C2 address via dead‑drop URLs on Telegram bots and Steam profiles, making forensic detection difficult. ACSC recommends restricting PowerShell execution, enabling application allow‑listing, and applying all available theme and plugin updates while removing unused components. The advisory also provides indicators of compromise (IoCs) that can be used to detect or block the malicious payloads. WordPress administrators should immediately audit their sites for compromised themes or plugins and apply security patches to mitigate the risk.

Key changes

  • ClickFix tricks users into executing malicious PowerShell commands via fake Cloudflare verification or CAPTCHA prompts on compromised WordPress sites.
  • Vidar Stealer deletes its executable after launch, runs from memory, and obtains its C2 address through dead‑drop URLs on Telegram bots and Steam profiles.
  • ACSC recommends restricting PowerShell execution and enabling application allow‑listing to mitigate the attack.
  • WordPress administrators are advised to apply all available theme and plugin updates and remove unused components.
  • ACSC provides indicators of compromise (IoCs) that can be used to detect or block the malicious payloads.
  • The advisory highlights that the attack uses compromised WordPress infrastructure to redirect users to malicious payloads.

Affects

wp-customers

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting