
India’s STPI serves TerminalFix-style attack via fake Cloudflare check
A website linked to India’s Software Technology Parks of India (STPI) is serving a spoofed Cloudflare verification page that silently copies a malicious string to visitors’ clipboards and prompts them to execute it via Windows Terminal, in a technique consistent with emerging TerminalFix-style attacks.
STPI, a Government of India organization that supports the country’s IT services and startup ecosystem, operates platforms used by technology firms, developers, and public-sector stakeholders.
The activity was observed on the ananta.stpi[.]in subdomain by cybersecurity researcher and red teamer Vibhum Dubey, who reported the issue to STPI and CERT-In, India’s Computer Emergency Response Team.
...