{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-700-education-and-tech-sites-hijacked-to-serve-clickfix-paste-the-comman"},"incident":{"slug":"2026-700-education-and-tech-sites-hijacked-to-serve-clickfix-paste-the-comman","title":"700+ education and tech sites hijacked to serve ClickFix paste-the-command lures","date":"2026-05","date_precision":"month","year":2026,"victim_org":"Visitors to 700+ compromised university and technology company websites","sector":"Education","country":"Global","primary_vector":"Watering Hole / Malvertising","secondary_vectors":["Tech Support Scam"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Service Disruption"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Reported in May 2026, attackers compromised more than 700 websites belonging mainly to education and technology organisations by exploiting CVE-2026-26980, a critical SQL injection flaw in Ghost CMS versions 3.24.0 to 6.19.0, to steal admin API keys without authentication. They then injected JavaScript that displayed fake Cloudflare and CAPTCHA verification dialogs instructing visitors to paste commands into the Windows Run dialog or PowerShell, installing Windows malware. No threat actor was named.","how_it_worked":"The CMS flaw only bought the attackers a place to stand; the compromise of each end victim still required the person to act. Instead of a checkbox, the verification dialog told visitors to copy a string and paste it into Run or PowerShell, framed as a routine anti-bot check. The trust signal was the host site itself, a university or technology vendor the visitor had chosen to visit, reinforced with countdown timers and fake user counters to compress the decision. Anyone who followed the instruction executed the attacker's installer with their own privileges.","lessons":"Group Policy or endpoint rules that block clipboard-driven shell execution neutralise every ClickFix variant regardless of the lure; patching Ghost CMS closes the injection route.","confidence":"Confirmed","sources":[{"title":"700+ education and tech websites hijacked in huge ClickFix malware campaign","url":"https://www.malwarebytes.com/blog/bugs/2026/05/700-education-and-tech-websites-hijacked-in-huge-clickfix-malware-campaign","publisher":"Malwarebytes"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-700-education-and-tech-sites-hijacked-to-serve-clickfix-paste-the-comman"}}