Additional Microsoft Defender tools and services that provide security across various platforms and environments
Clickfix attack on Azure Static webapp
Hi Sir/Mam,
We have deployed a nextjs application in Azure Static webapp. We started noticing a clickfix campaign attack on 18th July, 2026 where a fake captcha pop up is being injected on our website. We checked on our local build and found no issues. Hence, we redeployment and the issue was mitigated temporarily (for 2-4 hours). However, the campaign attack was auto injected through unknown means in out Azure static webapp. The attack is very similar to this reference: https://www.bleepingcomputer.com/forums/t/817363/sophisticated-clickfix-fake-captcha-campaign-full-ioc-writeup-help-identifyin/
For short term solution, we have whitelisted the URLs known to us that was being injected and thus prevented the pop up (2nd level payload) that was causing this but haven't yet been able to trace the root cause.
Any help and recommendations would be highly valuable!
Best,
Tushar