STPI Exploits Cloudflare Check for TerminalFix-Style Attack

STPI Exploits Cloudflare Check for TerminalFix-Style Attack

A website linked to India's Software Technology Parks of India (STPI) is using a spoofed Cloudflare verification page to execute a malicious script on Windows systems.

Bottom line: India's STPI has been exploited for a TerminalFix-style attack via a fake Cloudflare verification page.

What's happening: A website linked to STPI, which hosts the website of Indian IT services firm, HCL Technologies, has been found to be serving a malicious string via a spoofed Cloudflare verification page. The attack silently copies the string to visitors' clipboards and prompts them to execute it via Windows Terminal.

What to do: Security teams should monitor the website for signs of the attack and block traffic from known IP addresses associated with the attack.

Source: CSO Online