Bitcoin Forum
May 26, 2026, 07:50:00 PM *
News: Latest Bitcoin Core release: 31.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Fake CloudFlare verification screen - Beaware of the malware  (Read 80 times)
Shishir99 (OP)
Hero Member
*****
Offline

Activity: 1358
Merit: 928



View Profile
May 24, 2026, 09:53:44 AM
Merited by NeuroticFish (2), DYING_S0UL (2), TryNinja (1), Zwei (1)
 #1

I am creating this thread to spread awarness.

I have been seeing some reports on the internet that people are downloading malware on their computer without understanding and their computers are getting compromised. A several websites now using this trick to fool the users and the victims are downloading the malware thinking they are doing cloudflare verification to access the website or download some files.

Here are some of the screenshots that I saw online and there are more like this.

 

Cloudflare never ask you to press any button on the keyboard. Cloudflare verification mostly automatic. Bot fighting mode sometimes needs you to do captcha verification.

█████████████████████████
█████████████████████████
███████▀█████████▀███████
█████████████████████████
█████████████████████████
████████████▀████████████
███████▀███████▄███████
███████████▄▄▄███████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████

 2UP.io 
NO KYC
CASINO
██████████████████████████
████████████████████████
███████████████████████
███████████████████
██████████████████████
███████████████████████
███████████████████████
██████████████████
███████████████████████
██████████████████
███████████████████████
████████████████████████
██████████████████████████
███████████████████████████████████████████████████████████████████████████████████████
 
FASTEST-GROWING CRYPTO
CASINO & SPORTSBOOK

 

███████████████████████████████████████████████████████████████████████████████████████
███████████████████████████
█████████████████████████
███████████████████████
███████████████████████
████████████████████████
███████████████████████
███████████████████████
██████████████████████
████████████████████████
███████████████████████
███████████████████████
█████████████████████████
███████████████████████████
 

...PLAY NOW...
rohang
Sr. Member
****
Offline

Activity: 1886
Merit: 273



View Profile
May 24, 2026, 11:24:57 AM
 #2

Thanks for awareness on this.

Really well made and innovative by those people i must say, will scam many people with this sadly.

RAZED | 100%  
WELCOME
BONUS
█████████████████████
█████████████████████████
████████████▀░░░░▀███████
██████████▀░░▄▀▀▄░░▀█████
██████████▄▄██▄▄██▄░▀████
█████▀░░░░░░░▀██░░█░░████
████░░████▀▀█░░██▀░░▄████
████░░████▄▄█░░█░░▄██████
████░░█▀▀████░░██████████
████░░█▄▄███▀░░██████████
█████▄░░░░░░░▄███████████
█████████████████████████
█████████████████████
█████████████████████
█████████████████████████
██████████▀▀░░░░░▀▀██████
████████▀░░▄▄█░░▀▄░░█████
██████▀░░▄█████▄░░▀░░████
█████░░▄████▄▀░░█▄▄░░████
████░░▄███▄▀░░▄▀██▀░░████
████░░▀▀██░░▄▀███▀░░█████
████░░▄░░▀█████▀░░▄██████
█████░░▀▄░░█▀▀░░▄████████
██████▄▄░░░░░▄▄██████████
█████████████████████████
█████████████████████
|
NO
KYC
██████████████████
 RAZE THE LIMITS   PLAY NOW
██████████████████
PostQuantumBTC
Full Member
***
Offline

Activity: 233
Merit: 111



View Profile
May 24, 2026, 12:07:09 PM
 #3

This does not look like cloudflare at all

Another thing is that if you want to visit a site and you see the cloudflare, you will not see the name their site until you click on the link written in their name which is beside a link to privacy.

Also the cloudflare website is https://www.cloudflare.com/ but the one in that OP image is different which indicates it is not the original cloudflare.

noorman0
Hero Member
*****
Offline

Activity: 2016
Merit: 841


[Nope]No hype delivers more than hope


View Profile WWW
May 24, 2026, 12:21:53 PM
 #4

I wonder if these sites implemented this fake Cloudflare themselves, or if their sites is being compromised by attackers?
-snip-
but the one in that OP image is different which indicates it is not the original cloudflare.
Most uncritical users are impulsive and simply assume it's display update and verification method enhancement.

They don't even know why Cloudflare was implemented everywhere.

Yamane_Keto
Hero Member
*****
Offline

Activity: 868
Merit: 589


#kycfree


View Profile WWW
May 24, 2026, 01:46:50 PM
 #5

This is a lower level of Clipboard hijacking, and for this scam to succeed, the domain must be granted Clipboard access permissions. Random domains should not be allowed to receive these permissions.

TryNinja
Legendary
*
Offline

Activity: 3570
Merit: 10391


@ List of no-KYC websites: https://bitlist.co


View Profile WWW
May 24, 2026, 01:58:48 PM
 #6

This is a lower level of Clipboard hijacking, and for this scam to succeed, the domain must be granted Clipboard access permissions. Random domains should not be allowed to receive these permissions.
I don't think this is exactly true.

You can arbitrarily run navigator.clipboard.writeText(...) and all the user needs to do on most browsers is be on HTTPS (easy, Let's Encrypt) and any interaction to the website (like clicking on the "Verify" button). Nowhere you need to give any explicit permission. Also, if you're falling for a phishing scam you would do that to "verify" your access. Tongue

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
Shishir99 (OP)
Hero Member
*****
Offline

Activity: 1358
Merit: 928



View Profile
May 25, 2026, 01:46:23 PM
 #7

This does not look like cloudflare at all

Another thing is that if you want to visit a site and you see the cloudflare, you will not see the name their site until you click on the link written in their name which is beside a link to privacy.

Also the cloudflare website is https://www.cloudflare.com/ but the one in that OP image is different which indicates it is not the original cloudflare.

What makes you think I do not understand any of these things?

We are talking about the internet newbies who might fall for these scams. Since these scam methods are working, more and more scammers are using the same tricks, and people are falling for them. You don't need to visit cloudflare.com to face the Cloudflare verification. A lot of websites use the Cloudflare service to protect their website from DDoS attacks and from bots. If you are using a public IP address that is blacklisted, you will need to complete the verification to access that website.

█████████████████████████
█████████████████████████
███████▀█████████▀███████
█████████████████████████
█████████████████████████
████████████▀████████████
███████▀███████▄███████
███████████▄▄▄███████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████

 2UP.io 
NO KYC
CASINO
██████████████████████████
████████████████████████
███████████████████████
███████████████████
██████████████████████
███████████████████████
███████████████████████
██████████████████
███████████████████████
██████████████████
███████████████████████
████████████████████████
██████████████████████████
███████████████████████████████████████████████████████████████████████████████████████
 
FASTEST-GROWING CRYPTO
CASINO & SPORTSBOOK

 

███████████████████████████████████████████████████████████████████████████████████████
███████████████████████████
█████████████████████████
███████████████████████
███████████████████████
████████████████████████
███████████████████████
███████████████████████
██████████████████████
████████████████████████
███████████████████████
███████████████████████
█████████████████████████
███████████████████████████
 

...PLAY NOW...
Zwei
Legendary
*
Offline

Activity: 2030
Merit: 1203


Trêvoid █ No KYC-AML Crypto Swaps


View Profile WWW
May 25, 2026, 08:54:35 PM
 #8

i never came across this before, kinda smart not gonna lie.

I wonder if these sites implemented this fake Cloudflare themselves, or if their sites is being compromised by attackers?
i don't think someone running a website would be dumb enough to implement a fake cloudflare protection, so it's most likely either one of those annoying popup ads some sites use to monetize their traffic, or sites getting compromised.
if you use a good adblock you would not need to worry about having to deal with phishing attacks using ads 99% of the time.

also google recently introduced QR code captchas that you need to scan with your phone to prove you are not AI: https://cloud.google.com/blog/products/identity-security/introducing-google-cloud-fraud-defense-the-next-evolution-of-recaptcha#:~:text=New%20QR%2Dcode%20challenge%20in%20a%20shopping%20website.
i imagine the same trick could be used for that in a similar form, so people should be wary of that as well.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits PREDICT..
█████████████████████████
█████████████████████████
███████████▀▀░░░░▀▀██████
██████████░░▄████▄░░████
█████████░░████████░░████
█████████░░████████░░████
█████████▄▀██████▀▄████
████████▀▀░░░▀▀▀▀░░▄█████
██████▀░░░░██▄▄▄▄████████
████▀░░░░▄███████████████
█████▄▄█████████████████
█████████████████████████
█████████████████████████
.
.WHERE EVERYTHING IS A MARKET..
█████
██
██







██
██
██████
Will Bitcoin hit $200,000
before January 1st 2027?

    No @1.15         Yes @6.00    
█████
██
██







██
██
██████

  CHECK MORE > 
Shishir99 (OP)
Hero Member
*****
Offline

Activity: 1358
Merit: 928



View Profile
Today at 06:46:02 AM
 #9

Thanks for awareness on this.

Really well made and innovative by those people i must say, will scam many people with this sadly.

You're welcome.
Since some people have already fallen for it and become victims, I feel like it will work on others as well. All we can do is try to spread the awarness so more people see the new tricks, and they become cautious. When I saw that report online myself, I was also surprised to see that scammers are evolving and introducing new tricks to scam people. You will also find some Reddit threads about this scam.

█████████████████████████
█████████████████████████
███████▀█████████▀███████
█████████████████████████
█████████████████████████
████████████▀████████████
███████▀███████▄███████
███████████▄▄▄███████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████

 2UP.io 
NO KYC
CASINO
██████████████████████████
████████████████████████
███████████████████████
███████████████████
██████████████████████
███████████████████████
███████████████████████
██████████████████
███████████████████████
██████████████████
███████████████████████
████████████████████████
██████████████████████████
███████████████████████████████████████████████████████████████████████████████████████
 
FASTEST-GROWING CRYPTO
CASINO & SPORTSBOOK

 

███████████████████████████████████████████████████████████████████████████████████████
███████████████████████████
█████████████████████████
███████████████████████
███████████████████████
████████████████████████
███████████████████████
███████████████████████
██████████████████████
████████████████████████
███████████████████████
███████████████████████
█████████████████████████
███████████████████████████
 

...PLAY NOW...
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!