Campaign record
Cloudflare Turnstile iframe lure
Fake Cloudflare Turnstile landing page that copies its command from a hidden iframe
- Status as last assessed
- Active
- First seen
- 2025-05-22
- Last seen
- 2025-05-22
- Indicators
- 1
- Sources
- 1
- Targets
- Windows
- Fake browser verification challenge
Original research
- Microsoft Threat Intelligence2025-08-21Vendor researchFirst account
Think before you Click(Fix): Analyzing the ClickFix social engineering technique
This page summarises and structures that research; it is not a substitute for the original.
Researchers: if anything here misrepresents your work, email corrections@clickfixreport.com — we correct within 5 working days, no questions asked.
Summary
Microsoft takes one landing page apart as a worked example of how such a lure is put together. The visitor meets what appears to be a Cloudflare Turnstile check standing between them and the content. The markup pulls a stylesheet from the Font Awesome library to get the look right, and hides a second document, field.html, inside an invisible frame; that frame draws the tick box and animates a spinner when it is ticked. Ticking it makes the frame post a short message up to the page containing it, and on receiving that message the page writes an obfuscated command into the clipboard through the browser's clipboard interface, then shows the reader the steps for running it. Microsoft dates the page to 22 May 2025 and ties it to no payload family and no actor, so nothing further is claimed here.
Execution mechanisms
The only execution mechanism any published account describes for this campaign is Clipboard injection (T1204.004), which 15 of the 44 published campaigns in this corpus also record (34%).
Indicators
1 indicator, each present verbatim in at least one of the sources above. Values are shown defanged and are not links to the hosts — the link goes to our page for that indicator.
| Indicator | Type | Role | Assessment | First seen | Last seen | Report an error |
|---|---|---|---|---|---|---|
| domain, shown defanged for safety: binancepizza dot info | domain | Lure page | Not yet assessed | 2025-05-22 | 2025-05-22 | Report an error in domain record 52d99888-29cb-47fb-bbcd-22b6c0453c32 |
“Assessment” is who controls the host, not how dangerous it is. Many of these are compromised legitimate sites whose owners are victims, and they are excluded from every blocklist file we publish.
Not on this record
This record does not yet carry a second publisher's account, any overlap with another campaign in this corpus or our own re-checks of these indicators. Each appears on this page as its own section once it exists; none of it is inferred.
Cite as
ClickFixReport, “Cloudflare Turnstile iframe lure”, campaign ID 55c5b43f, retrieved 2026-08-07, snapshot fb0eed7.
https://clickfixreport.com/campaigns/55c5b43f/binancepizza-clickfix-turnstile-lure
Published under CC BY 4.0. Reuse it, including commercially, with attribution. The date above is when this record last changed, not when you opened it — the page is a versioned record, so that is the date a reader needs to find what you saw.