Clickfix attack on Azure Static webapp

Tushar Gopalka 0 Reputation points
2026-07-24T20:04:35.7633333+00:00

Hi Sir/Mam,

We have deployed a nextjs application in Azure Static webapp. We started noticing a clickfix campaign attack on 18th July, 2026 where a fake captcha pop up is being injected on our website. We checked on our local build and found no issues. Hence, we redeployment and the issue was mitigated temporarily (for 2-4 hours). However, the campaign attack was auto injected through unknown means in out Azure static webapp. The attack is very similar to this reference: https://www.bleepingcomputer.com/forums/t/817363/sophisticated-clickfix-fake-captcha-campaign-full-ioc-writeup-help-identifyin/

For short term solution, we have whitelisted the URLs known to us that was being injected and thus prevented the pop up (2nd level payload) that was causing this but haven't yet been able to trace the root cause.

Any help and recommendations would be highly valuable!

Best,

Tushar

Microsoft Security | Microsoft Defender | Other
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.