ClickFix distributing Vidar Stealer via WordPress

Published: 13/05/2026 01:41 AM Category: Alert CVE: N/A
CRITICAL SEVERITY

Fiji CERT Alert: ClickFix Campaign Distributing Vidar Stealer Malware

Overview

Fiji CERT is advising government agencies, businesses, critical infrastructure operators, website administrators, and the public of an emerging social engineering technique known as ClickFix, which has been actively observed globally since early 2024.

The technique is being used to distribute malware, including the well-known Vidar Stealer information-stealing malware, through compromised legitimate websites and deceptive fake verification prompts.

International cybersecurity agencies, including the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), have identified ClickFix campaigns targeting infrastructure and legitimate business websites. Similar attack methods may affect organizations and internet users within Fiji and the Pacific region.

What is ClickFix?

ClickFix is a sophisticated social engineering attack that tricks users into manually executing malicious commands on their devices.

The attack commonly uses:

  • Fake CAPTCHA verification pages

  • Fraudulent “Verify you are human” prompts

  • Fake Cloudflare verification screens

  • Browser pop-ups instructing users to copy and run commands

Unlike traditional malware attacks, ClickFix relies on user interaction, allowing attackers to bypass some automated security protections.

How the Attack Works

The attack typically begins when attackers compromise a legitimate website, often through vulnerable WordPress plugins, themes, or weak administrative security.

Once compromised:

  1. Malicious code is injected into the website.

  2. Users visiting the website are redirected to a fake verification page.

  3. A fraudulent CAPTCHA or Cloudflare verification prompt is displayed.

  4. The malicious website silently copies an obfuscated PowerShell command to the user’s clipboard.

  5. The user is instructed to paste and run the command with administrator privileges.

  6. The command downloads and executes the Vidar Stealer malware.

This process enables malware delivery with minimal warning signs to the victim.

About Vidar Stealer Malware

Vidar Stealer is a well-known information stealing malware targeting primarily Windows systems.

Once installed, Vidar can steal:

  • Saved browser passwords

  • Authentication cookies

  • Cryptocurrency wallet information

  • Banking credentials

  • System information

  • Browser history

  • Session tokens

  • Other sensitive data

The malware may also facilitate follow-on cybercrime activity, including:

  • Ransomware deployment

  • Business Email Compromise (BEC)

  • Credential abuse

  • Financial fraud

  • Identity theft


    Technical Behaviour Observed

Analysis of ClickFix activity shows that the malware uses several advanced defence-evasion techniques.

These include:

  • Obfuscated PowerShell commands

  • Self-deleting malware files

  • In-memory execution

  • Command-and-control (C2) communications

  • Use of legitimate platforms such as Telegram bots and Steam profiles as “dead drop” infrastructure

This behaviour makes detection and forensic analysis significantly more difficult.

Indicators of Suspicious Activity

Organizations should investigate immediately if users report:

  • Unexpected CAPTCHA or Cloudflare verification prompts

  • Requests to copy and paste commands into PowerShell

  • Browser prompts requesting administrative access

  • Suspicious PowerShell execution

  • Unusual outbound HTTP/S traffic

  • Credential theft incidents

  • Sudden browser session hijacking


    Fiji CERT Recommended Mitigations

For Website Administrators

Secure WordPress Environments

  • Keep WordPress fully patched and updated.

  • Remove unused or unsupported plugins and themes.

  • Apply security updates immediately.

  • Enable Web Application Firewall (WAF) protections.

Restrict Script Execution

  • Limit unauthorized JavaScript execution.

  • Monitor for malicious iframe injections.

  • Restrict clipboard manipulation from web content.

Harden Internet-Facing Systems

  • Prioritize patching externally accessible applications.

  • Conduct regular vulnerability assessments.

  • Monitor web server integrity and logs.

    For Organizations and Businesses

Restrict PowerShell Usage

  • Enforce PowerShell execution policies.

  • Prevent unauthorized scripts from running.

  • Restrict outbound PowerShell network connections.

Apply Least Privilege

  • Limit administrator privileges.

  • Prevent users from running commands as administrators unless necessary.

Enable Multi-Factor Authentication (MFA)

Implement phishing-resistant MFA for:

  • Administrative accounts

  • Remote access systems

  • Email services

  • Cloud platforms

Implement Network Protections

  • Filter malicious outbound traffic.

  • Use protective DNS services.

  • Monitor suspicious HTTP/S POST requests.

Maintain Secure Backups

  • Maintain regular offline backups.

  • Test restoration procedures regularly.

    Security Awareness Guidance

Fiji CERT strongly advises all users:

  • Never copy and paste commands from websites.

  • Never run PowerShell commands provided through pop-ups or CAPTCHA pages.

  • Be cautious of unexpected “verification” requests.

  • Report suspicious websites or behaviour immediately.

User awareness remains one of the most effective defenses against ClickFix-style attacks.

Fiji CERT Advisory

Fiji CERT encourages all organizations, government agencies, ISPs, and businesses to review their security posture and remain vigilant against evolving social engineering attacks.

Cybercriminals are increasingly targeting users directly through deception rather than exploiting technical vulnerabilities alone.

Strong cybersecurity awareness, secure configuration management, and proactive monitoring remain critical to protecting Fiji’s digital infrastructure.

Report Suspicious Activity

Fiji CERT

Stay vigilant. Think before you click. Never run commands from untrusted websites.