India’s STPI serves TerminalFix-style attack via fake Cloudflare check
Summary
A website linked to India's Software Technology Parks of India (STPI) is hosting a fake Cloudflare verification page that exploits a TerminalFix-style attack. This malicious page copies a command to the user's clipboard and prompts them to execute it in Windows Terminal, which would then initiate a request to attacker-controlled infrastructure.
IFF Assessment
This article describes a new attack technique being used on a government portal, posing a risk to users and highlighting a novel method for malicious execution.
Defender Context
Defenders should be aware of TerminalFix-style attacks that leverage trusted-looking interfaces on legitimate sites to trick users into executing malicious commands. This highlights the importance of user education and robust endpoint security to detect and block suspicious command executions, even when initiated from seemingly safe origins.