Product
Cloudflare Turnstile
- First Reported
- Aug 24, 2026
- Latest Reported
- Sep 30, 2026
Reported Context (3)
- The first actor-controlled domain serves as an initial filter; it conducts a Cloudflare Turnstile check behind a fake OneDrive loading screen before redirecting the target to an AitM credential phishing page hosted on a China-Aligned TA419 Uses Impersonation and AiTM Phishing to Target U.S. AI Policy Experts
- server at "account-access-rc3uenqi.elitechiropracticandrehab[.]com" and is presented with a Cloudflare Turnstile challenge. The root domain appears to belong to a legitimate chiropractic clinic, suggesting the GhostCode Phishing Kit Abuses Microsoft Device-Code Authentication to Steal Account Tokens
- Before being redirected to the final landing page, the redirector domains deploy a Cloudflare Turnstile or hCaptcha challenge to filter out automated crawlers, scanners, and bots. BengalSEO Uses SEO Poisoning and MayaBot to Drive Malware and Tech-Support Scams
Malware (1)
People (1)
Threat Actors (4)
MITRE ATT&CK (14)
Vendors (8)
Products (14)
Tools (11)
Industries (13)
Countries (6)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.