Malicious Clipboard Injection Attack Targets Users on Indian Government Site

Sep 11, 2026 469 views

A concerning cybersecurity breach has emerged involving a website associated with India's Software Technology Parks of India (STPI). The site, ananta.stpi[.]in, has been found to distribute a counterfeit Cloudflare verification page that subtly copies a malicious command to users' clipboards, coaxing them into executing it via Windows Terminal. This tactic mirrors tactics seen in TerminalFix-style attacks.

STPI, a governmental body that aids India's IT services and startup ecosystems, provides a platform for technology companies and developers. Security researcher and red team expert Vibhum Dubey uncovered this issue and promptly notified STPI along with CERT-In, India’s Computer Emergency Response Team.

A review by CSO found that a suspicious external JavaScript remained embedded within the site's source code even after the attack was temporarily resolved, indicating that the threat may persist.

How the Fake Verification Works

The counterfeit page emulates a typical Cloudflare “Verify you are human” prompt but goes a step further by instructing users to access Windows Terminal, paste a command, and hit Enter. The string of code is preloaded into the clipboard without user action, revealing the potential for abuse. Dubey observed that this command, if executed, would trigger a request to an external server controlled by the attackers. He refrained from executing the command himself.

Security tools identified the URL as malicious, with 17 detection engines on VirusTotal flagging it at the time of analysis. This method redirects execution responsibility from the browser to the endpoint, relying on user interactions rather than typical payload delivery.

“What struck me is the attack occurred on a government website,” Dubey noted. “Users trust ananta.stpi[.]in for accessing STPI services, so when presented with a seemingly normal verification check, they might unwittingly follow the instructions.” His observation highlights the effectiveness of such tactics in exploiting user trust.

Connections to TerminalFix

The observed technique aligns closely with an attack pattern categorized by Microsoft as TerminalFix, closely related to ClickFix threats. These tactics utilize mimicked verification pages to prompt users into executing commands locally, slipping past traditional web security measures.

“This adheres to the playbook: spoofed verification page, clipboard injection, and terminal execution instructions,” Dubey explained, noting that Microsoft has recorded similar behavior in its TerminalFix analyses. Although there's no attribution to specific attack campaigns, the overlapping tactics can’t be ignored.

The Role of Staged Delivery

Analysis of the source code revealed an external script from cdn[.]quickdelivr[.]com—a domain less than a week old and resembling the legitimate jsDelivr CDN. Dubey found that both the overlay and clipboard manipulation stemmed from this script, a conclusion verified independently by CSO.

According to Dubey, this tactic allows the attacker to manage command-and-control configurations on external servers, complicating efforts to mitigate the threat. The script is heavily obfuscated and runs within a virtual machine in the browser, making it harder to analyze. Its implementation assigns unique identifiers to each visitor, indicating a degree of session tracking is in play.

Concerns Regarding External Configuration

Despite a temporary disappearance, the fake verification page has re-emerged, suggesting that the mechanisms behind this malicious behavior remain operative. Dubey pointed out possible vulnerabilities in the site’s WordPress setup, specifically noting that differential error messages could reveal valid administrator usernames. Determining whether these vulnerabilities were exploited would necessitate server-side analysis.

“The implications are troubling since this is a government-affiliated site,” Dubey emphasized. The audience includes IT professionals and officials; executing the command on a work system could lead to credential exposure or unauthorized access to sensitive environments.

CERT-In has acknowledged Dubey's report and mentioned they are “in the process of taking appropriate action with the concerned authority,” though STPI had not responded to CSO’s inquiries at the time of publication.

Source: James Smith · www.csoonline.com

Comments

Sign in to comment.
No comments yet. Be the first to comment.

Related Articles

India’s STPI serves TerminalFix-style attack via fake Clo...