ClickFix Attacks Escalate: Ghost CMS Mass Compromise via CVE-2026-26980 Enables Clipboard-Based Payload Delivery
More than 700 legitimate websites running Ghost CMS have been compromised and weaponized to deliver ClickFix malware through fake CAPTCHA overlays [1]. The campaign, first detected on May 7, 2026 by QiAnXin XLab, exploits CVE-2026-26980, an unauthenticated SQL injection vulnerability in Ghost's Content API with a CVSS score of 9.4 [1][2]. The attackers extract Admin API keys from the database, then use the Ghost Admin API to inject malicious JavaScript loaders into article pages at scale [1]. At least two distinct threat clusters are operating concurrently, sometimes re-infecting the same sites within a single day of cleanup [1].
The victims span universities, blockchain companies, AI startups, SaaS platforms, security research blogs, media outlets, and fintech firms [1]. By hijacking trusted domains rather than registering disposable infrastructure, these operators bypass domain reputation filters and URL blocklists that form the first line of defense for most organizations.
Background: ClickFix's Evolution from Commodity Trick to Persistent Threat
Proofpoint publicly documented ClickFix in June 2024, tracing campaigns from TA571 back to early March 2024 [3]. The technique is straightforward: a fake error message, browser prompt, or CAPTCHA page instructs the victim to open a system utility (Run dialog, Terminal, PowerShell) and paste a command. JavaScript on the attacker's page silently loads that command into the clipboard. The victim executes it voluntarily. No malicious file touches disk. The process tree looks legitimate. Most endpoint controls never fire.
By April 2025, Proofpoint reported that state-sponsored actors from North Korea (TA427), Iran (TA450), and Russia (UNK_RemoteRogue, TA422) had all experimented with ClickFix between October 2024 and early 2025 [4]. TA427 returned with a slightly varied infection chain in April 2025 [4]. Proofpoint noted that no single actor had shown sustained repeated use in the weeks immediately following initial campaigns, but the technique kept spreading to new groups [4].
The appeal is structural. Browser sandboxes don't inspect clipboard contents. UAC prompts often don't fire because the user is manually opening a trusted system utility. Security awareness training still focuses on malicious links and attachments, not on commands users paste into their own terminal. ClickFix sits in a gap between what security tools monitor and what users are trained to suspect.
CVE-2026-26980: The Ghost CMS Entry Point
The vulnerability at the center of the current campaign is CVE-2026-26980, a SQL injection flaw in Ghost's Content API slug filter ordering [1][2]. It affects Ghost CMS versions 3.24.0 through 6.19.0 and allows unauthenticated reads of arbitrary database data [1][2]. The flaw was patched in February 2026 with version 6.19.1 [1][5].
The attack sequence works as follows:
- The attacker sends crafted requests to the Content API, exploiting the SQL injection to dump database contents.
- Admin API keys are extracted from the database without any authentication.
- Using valid Admin API credentials, the attacker calls the Ghost Admin API to modify articles in bulk.
- Malicious JavaScript loaders are appended to the bottom of article pages [1].
QiAnXin XLab described this as "large-scale poisoning" [1]. The injected code renders a fake Cloudflare or CAPTCHA verification overlay on top of the legitimate page content. Visitors see what appears to be a standard verification step on a domain they already trust.
Stage 1: Lure Presentation
When a visitor loads a compromised Ghost CMS article, the injected JavaScript renders a full-screen overlay mimicking a Cloudflare challenge or standard CAPTCHA. The overlay is visually consistent with legitimate verification prompts, making it difficult for end users to distinguish from the real thing.
Stage 2: Clipboard Staging
The JavaScript silently copies a command string to the victim's clipboard. The overlay instructs the user to open a system utility and paste the command to "verify" they are human.
Stage 3: User-Initiated Execution
The victim opens the Run dialog (Win+R), PowerShell, or Terminal and pastes the command. Because the user initiates the process manually from a trusted system utility, endpoint detection tools generally don't flag the activity. There's no malicious binary drop, no macro-enabled document, no exploit of a browser vulnerability.
Stage 4: Payload Delivery
The pasted command typically fetches and executes a second-stage payload. Observed variants have included PowerShell download cradles, portable Python environments bundled with malicious scripts, and MSHTA-based execution chains. The portable Python approach is particularly effective because it guarantees execution regardless of whether Python is installed on the target system.
Two Threat Clusters, One Technique
QiAnXin XLab identified at least two separate threat clusters operating within this campaign [1]. Both exploit the same vulnerability and use the same injection technique, but they appear to operate independently. In some cases, both clusters implanted malicious code on the same domain, and re-infection occurred within a single day after site administrators cleaned up the initial compromise [1]. This parallel operation suggests either shared tooling sold on underground markets or independent discovery and exploitation of the same vulnerability.
MITRE ATT&CK Mapping
Based on the observed campaign behaviors described in the source material:
| Technique ID | Name | Context |
|---|---|---|
| T1190 | Exploit Public-Facing Application | Exploitation of CVE-2026-26980 in Ghost CMS Content API [1][2] |
| T1059.001 | Command and Scripting Interpreter: PowerShell | Victims paste and execute PowerShell commands from clipboard [3] |
| T1204 | User Execution | Users manually execute attacker-supplied commands pasted from clipboard. No precise sub-technique exists for command-paste execution; T1204 at the parent level is the closest mapping [3] |
| T1659 | Content Injection | Malicious JavaScript injected into legitimate Ghost CMS article content to render fake CAPTCHA/Cloudflare overlays [1] |
| T1584.004 | Compromise Infrastructure: Server | Legitimate Ghost CMS sites compromised and used as delivery infrastructure [1] |
| T1189 | Drive-by Compromise | Victims compromised by visiting legitimate but poisoned Ghost CMS pages [1] |
Note: Clipboard staging (writing malicious commands to the victim's clipboard) lacks a precise ATT&CK technique mapping. T1115 (Clipboard Data) is the closest available technique but traditionally describes reading clipboard contents rather than writing to it.
Ghost CMS Compromise Indicators
Defenders managing Ghost CMS instances should audit article content for injected <script> tags that weren't authored by legitimate users. Query the Ghost Admin API audit log for bulk article modifications, particularly those originating from API keys rather than interactive sessions. Any Ghost CMS instance running versions 3.24.0 through 6.19.0 should be treated as potentially compromised until verified [1][2].
Network-Level Detection
Monitor for outbound connections from endpoints immediately following user interaction with Run dialog or PowerShell. A user opening powershell.exe or cmd.exe and immediately making an HTTP/HTTPS request to an external domain is a strong behavioral signal.
Endpoint Telemetry
Look for process chains where explorer.exe spawns powershell.exe, cmd.exe, or mshta.exe with command-line arguments containing encoded or obfuscated content. The clipboard-to-execution pattern produces a distinctive process tree.
Sigma Rule: ClickFix Execution Pattern
title: Suspicious Command Execution via Run Dialog Consistent with ClickFix
id: a3f1c8e2-9d4b-4e7a-b6c5-2f8d1a3e9b7c
status: experimental
description: Detects execution of PowerShell or cmd with encoded/obfuscated arguments spawned from explorer.exe, consistent with ClickFix clipboard paste attacks
author: RedSheepSec
date: 2026/09/04
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith: '\explorer.exe'
selection_child:
Image|endswith:
- '\powershell.exe'
- '\cmd.exe'
- '\mshta.exe'
selection_args:
CommandLine|contains:
- 'encodedcommand'
- 'frombase64'
- 'downloadstring'
- 'invoke-expression'
- 'iex'
- 'hidden'
condition: selection_parent and selection_child and selection_args
falsepositives:
- Legitimate administrative scripts launched via Run dialog
level: high
tags:
- attack.execution
- attack.t1059.001
- attack.t1204
Proxy and Web Filter Hunting
Organizations that proxy web traffic should look for pages that load JavaScript setting navigator.clipboard or document.execCommand('copy') in combination with overlay elements styled to mimic CAPTCHA or Cloudflare challenges. Content inspection rules can flag pages where clipboard manipulation occurs alongside full-screen overlay rendering.
Analysis
The Ghost CMS campaign represents a meaningful escalation in ClickFix operations. Previous campaigns relied on attacker-controlled domains or compromised WordPress sites. This campaign targets a specific CMS vulnerability at scale, affecting over 700 sites across diverse sectors [1]. The involvement of two separate threat clusters operating concurrently suggests the exploitation methodology is likely either being shared or sold, and that the technique has graduated from opportunistic experimentation to structured operations.
The patching gap is significant. Ghost released version 6.19.1 in February 2026 [1], but the campaign was detected in May 2026, three months later. Hundreds of instances remained vulnerable. This pattern is consistent with self-hosted open-source CMS deployments, where patching discipline lags behind commercial SaaS platforms.
The technique's adoption by state-sponsored actors from North Korea, Iran, and Russia in 2024-2025 [4] established its credibility. The current mass-exploitation campaign demonstrates that criminal operators have likely absorbed those lessons and operationalized them at scale.
Red Sheep Assessment
Confidence: Moderate
The sources collectively point to a conclusion none of them explicitly state: ClickFix is likely transitioning from a social engineering trick into a delivery platform with its own supply chain. The Ghost CMS campaign is not just about one vulnerability. It demonstrates a repeatable pattern: find a CMS with an API-accessible content layer, exploit an auth bypass or injection flaw to obtain API credentials, then use legitimate content management functions to inject the lure at scale. Ghost CMS is the current target. Any CMS with a similar API architecture and a comparable vulnerability could be a candidate for the same treatment.
The two-cluster observation from QiAnXin XLab [1] is particularly telling. Parallel exploitation by independent groups, with re-infection after cleanup, points toward either a shared exploit kit or independent convergence on the same technique. Either way, it means patching alone is unlikely to be sufficient. Compromised sites need full credential rotation, API key revocation, and content auditing even after patching.
A contrarian reading: the 700-site figure, while large, may overstate the campaign's impact. Many Ghost CMS sites have modest traffic. The conversion rate from page visit to actual payload execution depends entirely on user behavior, and security-aware users at universities and security research blogs may be less susceptible than average. Still, even a low conversion rate across 700 sites with diverse audiences likely produces meaningful victim volume.
Defender's Checklist
- ▢[ ] Patch Ghost CMS immediately. Upgrade all instances to version 6.19.1 or later. Versions 3.24.0 through 6.19.0 are vulnerable to CVE-2026-26980 [1][2].
- ▢[ ] Rotate all Ghost Admin API keys on any instance that ran a vulnerable version, even after patching. Attackers extract keys via SQL injection before the patch is applied [1].
- ▢[ ] Audit Ghost CMS article content for injected
<script>tags or JavaScript loaders appended to article bodies. Check the Admin API audit log for bulk modifications from API key sessions. - ▢[ ] Deploy endpoint detection for ClickFix execution patterns. Monitor for
explorer.exespawningpowershell.exe,cmd.exe, ormshta.exewith encoded or download-related command-line arguments. Use the Sigma rule provided above. - ▢[ ] Update security awareness training to include clipboard-based social engineering attacks. Specifically, train users to never paste commands from websites into PowerShell, Terminal, cmd.exe, or the Windows Run dialog. Provide visual examples of fake CAPTCHA/Cloudflare overlays that instruct users to run commands.
References
- Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks - The Hacker News
- Active Exploitation Alert: Ghost CMS CVE-2026-26980 Mass Attack Hijacks 700+ Sites for ClickFix Malware Campaigns - Rescana
- ClickFix: Social Engineering Technique Floods Threat Landscape - Proofpoint (June 2024)
- State-Sponsored Actors Adopt ClickFix - Proofpoint (April 2025)
- Ghost has a SQL injection in Content API - GitHub Advisory Database (GHSA-w52v-v783-gw97)