Lure theme
Cloudflare Turnstile clone
A close imitation of Cloudflare's browser-check interstitial — the page millions of people see and dismiss without reading. It borrows the layout, the wording and usually a fabricated reference identifier so that whatever follows reads as part of a routine security check. Technically it is a fake-CAPTCHA lure; it earns its own entry because the costume is specific, extremely familiar, and unusually well made.
- First reported
- 2024-10
- Targets
- Windows · macOS
- Campaigns on record
- 5
Approximate. Turnstile-styled clones appear alongside the wider fake-CAPTCHA wave in late 2024 and are rarely dated separately from it.
Also reported as Fake Turnstile · Fake Cloudflare check · Checking your browser lure · Ray ID lure
What a victim sees
The familiar interstitial: one line about the connection being checked, a small verification control, a footer crediting a security provider, and a reference identifier rendered as hexadecimal. The imitation is generally good — spacing, typeface and colour are close, and it is served over HTTPS, often from a domain that resembles the one the visitor wanted. The divergence comes at the end. A genuine check clears itself; this one reports a problem and offers a manual step, and the manual step is a paste-and-run sequence.
Described rather than shown. This site publishes no screenshots of lure pages and reproduces none of their markup, because a working copy of a fake verification page is a fake verification page regardless of why it was made.
The tell-tale sign
A genuine Cloudflare check is passive. It resolves on its own and asks you for nothing at all — least of all the Run dialog or Terminal.
The underlying rule is the same for every theme on this site, and it is the one worth remembering: no legitimate website will ever ask you to press Windows+R, to open Terminal, or to paste anything into either one. Why that rule holds.
Campaigns using this lure
MIMICRAT via compromised websites
Status as last assessed: ActiveElastic Security Labs first described this operation, in which a copy-and-paste prompt on compromised websites leads the visitor to run a command that installs a RAT called MIMICRAT. Stormshield found the campaign still running and, on 3 March 2026, pivoted from the two payload servers Elastic had named. Passive DNS on those addresses returned a large estate of look-alike service names - variations on 'avservice', 'msmanager', 'winservice' and similar - spread across the .network, .cc, .lat, .info, .wiki, .live and .pics top-level domains. Almost all were registered through the same registrar, most in early January 2026, and some on the day the report was written. Stormshield notes it expects more to appear. A second pivot, on a 'hosting is blocked' banner returned by one server, produced five further addresses. The report adds thirty-one file hashes, most of them TLS certificates rather than malware.
ID 2b5d663aFirst seen 2026-02-11Last seen 2026-03-03WindowsOdyssey Stealer's shared codebase
Status as last assessed: ActiveThree page variants, one codebase. Each reads the user-agent string and hands out a different clipboard payload per platform, and in every case the text on screen is not the text that gets copied. The first serves macOS a Base64-wrapped shell command that fetches Odyssey, and Windows a PowerShell line for a payload Unit 42 could not name. The second targets macOS and gives Windows only a harmless decoy that completes the lure without infecting anything, at times with Cyrillic letters standing in for Latin ones in the domain shown. The third drops the branching and offers the macOS command alone, backgrounded so that closing the window does not stop it. Layout and function naming match across all of them, some carry Russian developer comments left in place, and every C2 traced back to Odyssey, which its operator sells as a service on Exploit and XSS.
ID f97086c9First seen 2025-04-14Last seen 2025-09-18macOS · WindowsIUAM ClickFix Generator
Status as last assessed: ActiveUnit 42 found the builder rather than only its output. An open HTTP server on TCP port 3000 ran an Express web application, styled with Tailwind, whose single job was producing counterfeit browser-verification pages. An operator fills in a form: page title, spoofed domain, the wording of the widget, footer and instruction panel, and above all the string that gets placed silently into a visitor's clipboard. Further options cover obfuscation, automatic clipboard-copy injection, a prompt telling phone users to move to a computer, and detection of the visitor's platform so Windows sees one instruction and macOS another. The host was reachable from mid-July 2025 into early October. Unit 42 treats the find as evidence of commoditisation: rival kits competing to package the technique for buyers who lack the skill to write one.
ID bef1cd04First seen 2025-07-18Last seen —Cross-platformCloudflare Turnstile iframe lure
Status as last assessed: ActiveMicrosoft takes one landing page apart as a worked example of how such a lure is put together. The visitor meets what appears to be a Cloudflare Turnstile check standing between them and the content. The markup pulls a stylesheet from the Font Awesome library to get the look right, and hides a second document, field.html, inside an invisible frame; that frame draws the tick box and animates a spinner when it is ticked. Ticking it makes the frame post a short message up to the page containing it, and on receiving that message the page writes an obfuscated command into the clipboard through the browser's clipboard interface, then shows the reader the steps for running it. Microsoft dates the page to 22 May 2025 and ties it to no payload family and no actor, so nothing further is claimed here.
ID 55c5b43fFirst seen 2025-05-22Last seen 2025-05-22WindowsLatrodectus from Storm-0249
Status as last assessed: ActiveStorm-0249, a group Microsoft associates with Latrodectus and other first-stage malware, changed its way in at the start of March 2025. Where it had sent PDFs or links by mail, sometimes themed around copyright complaints, it began taking over legitimate websites — possibly through weaknesses in WordPress — and grafting a lure onto them. A visitor sees the genuine page for a moment before it is swapped for a demand to prove they are human, dressed up as a Cloudflare Turnstile check so the interruption reads as routine. Doing as instructed means pasting a command into the Windows Run dialog. The owners of the hosting sites are victims here, not participants; Microsoft names none of them. The host reached by the pasted command is recorded as cqsf[.]live, seen on 14 May 2025.
ID 0216315eFirst seen 2025-05-14Last seen 2025-05-14Windows