We recently wrote about the sharp rise in automated attacks on websites we are seeing and why security now is more important than ever.
We’ve seen more attacks in the past few months than ever before, and whilst typical attacks would usually just bring the website down, a recent compromise enabled a malicious plugin to be installed, which generated a ‘ClickFix’ attack for front-end users on the site.
This attack essentially showed a fake Cloudflare verification method asking the user to run commands on their device, which would then install malware directly on their own device.
How the attackers got in
The site was compromised through an admin account that was not hardened through 2 Factor Authentication and whose password had been shared internally and sat in a readable chat history.
How it ended up on the site
The attack enabled a plugin to be installed on the site called “WordefenceSec”, a deliberate misspelling of the leading WordPress security plugin Wordfence.
Once active, the plugin added a piece of code to every public page on the site.
That code reached out to a server controlled by the attackers and pulled down the fake Cloudflare verification screen that visitors then saw.
The setup meant the attackers could change what was being shown at any time without needing to touch the site again.
What to look out for as a visitor
With that fake verification screen in place, the attackers had a direct line to anyone visiting the site.
The screen was designed to get visitors to run a command on their own computer, which would then let the attackers pull information straight off it.
Knowing what one of these screens actually asks you to do is the best way to spot one.
Specific things this ‘ClickFix’ requested:
- An instruction to press the Windows key + R, or to open the Run dialog, Terminal, or PowerShell.
- An instruction to paste something and press Enter.
- A “verification failed, please complete these steps” style message with numbered instructions.
- A Cloudflare or Google verification screen on a page where it doesn’t belong, for example, a normal content page you’re just reading, rather than a login or form submission.
- Keyboard shortcut prompts you don’t recognise, particularly anything involving Ctrl+V or Win+V after a page has loaded.
- A short countdown or urgency prompt telling you to complete the steps quickly, which is there to stop you thinking about what you’re being asked to do.
What would happen if they did run this command?
If a visitor followed the steps, a small program would install itself on their computer and start collecting saved passwords, active browser logins, and other credentials stored on the machine.
The damage tends to surface days or weeks later, when accounts start being accessed from unfamiliar locations, or money starts moving.
What security-first actually looks like
The rise in attacks is not slowing down, and incidents like this one are becoming the norm rather than the exception.
Our security-first approach is across everything we do, and we apply this across every site we manage.
Our sites need constant attention, and our clients need to be communicated with to ensure they are abreast of the recent developments we are seeing.
At a baseline, two-factor authentication should be enforced on every account with access to the site, including any held by third-party agencies, with no exceptions.
Admin access should be reviewed regularly, and anyone who no longer needs it should be removed.
Every plugin installed across the site should be centrally monitored, with alerts on new installs and on any newly disclosed vulnerabilities.
It is no longer enough to perform scheduled plugin updates. Plugins are changing so quickly that they need to be proactively monitored, and this is something we have enabled through our central dashboard.
Our team gets alerts on any newly disclosed vulnerabilities, which they can monitor and make sure they apply appropriate patches too. Anything flagged as a high or critical vulnerability is patched the moment it’s picked up, not held over for the next scheduled window.
The threat landscape has shifted, and the way sites are looked after has to shift with it.
You need to be proactive, and you need the agency looking after your site to be too. That means monitoring, patching, and flagging risks before they become incidents, not reporting on them after the fact.