Skip to content

Campaign record

Cloudflare Turnstile iframe lure

Fake Cloudflare Turnstile landing page that copies its command from a hidden iframe

Status as last assessed
Active
First seen
2025-05-22
Last seen
2025-05-22
Indicators
1
Sources
1
Targets
Windows
  • Fake browser verification challenge

Original research

This page summarises and structures that research; it is not a substitute for the original.

Researchers: if anything here misrepresents your work, email corrections@clickfixreport.com — we correct within 5 working days, no questions asked.

Summary

Microsoft takes one landing page apart as a worked example of how such a lure is put together. The visitor meets what appears to be a Cloudflare Turnstile check standing between them and the content. The markup pulls a stylesheet from the Font Awesome library to get the look right, and hides a second document, field.html, inside an invisible frame; that frame draws the tick box and animates a spinner when it is ticked. Ticking it makes the frame post a short message up to the page containing it, and on receiving that message the page writes an obfuscated command into the clipboard through the browser's clipboard interface, then shows the reader the steps for running it. Microsoft dates the page to 22 May 2025 and ties it to no payload family and no actor, so nothing further is claimed here.

Execution mechanisms

The only execution mechanism any published account describes for this campaign is Clipboard injection (T1204.004), which 15 of the 44 published campaigns in this corpus also record (34%).

Indicators

1 indicator, each present verbatim in at least one of the sources above. Values are shown defanged and are not links to the hosts — the link goes to our page for that indicator.

Indicators recorded for this campaign, shown defanged
IndicatorTypeRoleAssessmentFirst seenLast seenReport an error
domain, shown defanged for safety: binancepizza dot infodomainLure pageNot yet assessed2025-05-222025-05-22Report an error in domain record 52d99888-29cb-47fb-bbcd-22b6c0453c32

“Assessment” is who controls the host, not how dangerous it is. Many of these are compromised legitimate sites whose owners are victims, and they are excluded from every blocklist file we publish.

Not on this record

This record does not yet carry a second publisher's account, any overlap with another campaign in this corpus or our own re-checks of these indicators. Each appears on this page as its own section once it exists; none of it is inferred.

Cite as

ClickFixReport, “Cloudflare Turnstile iframe lure”, campaign ID 55c5b43f, retrieved 2026-08-07, snapshot fb0eed7.

https://clickfixreport.com/campaigns/55c5b43f/binancepizza-clickfix-turnstile-lure

Published under CC BY 4.0. Reuse it, including commercially, with attribution. The date above is when this record last changed, not when you opened it — the page is a versioned record, so that is the date a reader needs to find what you saw.