← Back to feed
Vendors & MarketEmerging1 sourceSep 11, 2026 · 15:26via CSO Online

India’s STPI serves TerminalFix-style attack via fake Cloudflare check

Brief

A website linked to India’s Software Technology Parks of India (STPI) is serving a spoofed Cloudflare verification page that silently copies a malicious string to visitors’ clipboards and prompts them to execute it via Windows Terminal, in a technique consistent with emerging TerminalFix-style attacks.

STPI, a Government of India organization that supports the country’s IT services and startup ecosystem, operates platforms used by technology firms, developers, and public-sector stakeholders.

The activity was observed on the ananta. stpi[. ]in subdomain by cybersecurity researcher and red teamer Vibhum Dubey , who reported the issue to STPI and CERT-In, India’s Computer Emergency Response Team.

Read more on CSO Online→