Fake Cloudflare Pages on 700 Sites Including Harvard and DuckDuckGo: Two Criminal Groups Fought Over Them

700+ sites including Harvard and DuckDuckGo delivered malware via fake Cloudflare Pages. Two rival criminal gangs fought over the compromised domains.

Fake Cloudflare Pages on 700 Sites Including Harvard and DuckDuckGo: Two Criminal Groups Fought Over Them
Malware

Illustrative image generated with AI

The operation discovered on July 30: universities, search engines, and hundreds of compromised domains

More than 700 websites – including domains belonging to Harvard and Oxford universities and the DuckDuckGo search engine – were used as malware distribution platforms. On July 30, 2026, the scale of the attack was disclosed, affecting unrelated entities connected only by a shared malicious infrastructure.

The code injection, identified through Netcraft’s analysis, was spread across hundreds of seemingly independent pages. Visitors to those sites were redirected or shown a fake Cloudflare verification screen, designed to bypass suspicion and deliver the payload.

The fake Cloudflare page and the ClickFix technique

The screen displayed the typical “Checking your browser” message from the legitimate service, instructing the user to press a key combination and paste a command into the terminal or the Windows Run dialog. This technique—known as ClickFix—exploits trust in the Cloudflare brand to trick the victim into personally executing the malicious script.

Once the command was copied and pasted, malware was downloaded aimed at credential theft and remote device control. This occurred without breaching the site-owning organization itself, instead leveraging client-side compromise and the trust placed in the displayed brand.

Two rival gangs at war over the same breached sites

A detail revealed by the investigation is that two distinct criminal groups were vying for control of the same compromised domains. The injected code contained references to different command-and-control (C2) infrastructures, indicating that the attackers were stealing access to already-hacked sites from each other.

This internal conflict within organized crime shows that brand impersonation is no longer an occasional ploy: it is a contested asset, capable of generating steady profits and worth fighting over.

Impersonation as a systemic vector: the numbers

The attack is part of a documented phenomenon. As early as 2022, the FBI had flagged the abuse of search ads to impersonate brands (search-ad impersonation). In the first quarter of 2026, the Anti-Phishing Working Group (APWG) recorded 971,181 phishing attacks, a 13.8% increase over the previous quarter, with a growing share tied precisely to brand impersonation.

This is therefore not a single incident, but a structural initial access vector: the attacker doesn’t enter the organization but interposes itself between the brand and its customers using compromised domains, fake apps, counterfeit social media accounts, or malicious advertising campaigns.

Why firewalls, SEGs, and DNS blocklists are not enough

Traditional defenses—firewalls, secure email gateways, DNS blocklists—act on the corporate perimeter. Blocking a domain on a local blacklist does not prevent that domain from remaining active for the rest of the world, nor the infrastructure from being regenerated within hours under a new name.

The result is a “whack-a-mole” effect: security, legal, and marketing teams toss the problem back and forth without a single owner of the detection and takedown process. Reputational damage and loss of trust grow while criminals shift the load to another domain.

Taking down the infrastructure as if it were a C2

Netcraft, in its “Field Guide to Brand Protection,” proposes a change in approach: treat impersonation infrastructure exactly like a botnet or a command-and-control server.

Mapping attackers’ operational patterns—shared ASNs, recurring hosting providers, SSL certificate issuers—makes it possible to correlate seemingly distinct campaigns and strike common nodes. Added to this is the definition of a measured SLA for takedown (time from detection to removal) and the assignment of a single responsibility within the organization, overcoming fragmentation among legal, SOC, and communications.

The episode of the 700 sites shows that the difference between a contained incident and systemic damage lies in the ability to shut down the infrastructure before two criminal gangs fight over it by reinjecting each other’s code.

Read next

Sources

This article is an original reworking based on the sources below.

Back to home

Latest Cybersecurity News

All cybersecurity news →