Security News

Cybersecurity news aggregator

MEDIUM Attacks Dark Reading

ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain

  • What: ClickFix campaign uses Polygon blockchain for C2 server obfuscation
  • Impact: 31 organizations compromised
Read Full Article →

Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources ENDPOINT SECURITY REMOTE WORKFORCE CYBERATTACKS & DATA BREACHES THREAT INTELLIGENCE NEWS ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain The campaign uses EtherHiding to dynamically update its command-and-control server, abusing the blockchain as an attacker-controlled address book. Elizabeth Montalbano,Contributing Writer September 1, 2026 5 Min Read SOURCE: IN CAMERA STOCK VIA ALAMY STOCK PHOTO Attackers have compromised at least 31 organizations through a ClickFix campaign that abuses the Polygon blockchain technology in a technique known as "EtherHiding" to obscure and automate its malicious activity. The campaign already has attacked the websites of various organizations, including businesses in e-commerce, professional services, and retail logistics, according to a report released today by GuidePoint Security’s Research and Intelligence Team (GRIT). The report is based on GRIT's findings on blockchain forensics, incident-response evidence, and analysis of the malware’s source code. The attack uses a technique that emerged several years ago called EtherHiding, which abuses blockchain technology to cover up malicious activity. In this case, the attackers use the Polygon cryptocurrency blockchain — a permanent, distributed ledger — to dynamically update their command-and-control (C2) servers rather than use a fixed C2 server address, which is more easily detected and blocked. Related:'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month "Because it allows for ad hoc adjustment of C2 details at scale, blocking a singular domain or IP address alone does not permanently sever attacker access," Jean-Pierre Mouton, senior threat intelligence consultant for GuidePoint, wrote in the report. "For fractions of a cent per transaction, the attacker can redirect every infected machine to a new C2 server automatically." This differs from most ClickFix campaigns, in which an infostealer is deployed on the victim's system that can be neutralized by blocking the attacker’s C2 server, cutting off communications with infected machines, he said. ClickFix with Some Twists LOADING... EtherHiding has been around for a few years now, but it has mostly been limited to Binance or Etherium, Mouton tells Dark Reading. One thing that sets the campaign apart from others using this tactic, then, is the use of Polygon smart contracts rather than those blockchain technologies, he says. The attackers also put a new twist on ClickFix by using "a Search Engine Poisoning system and malicious JavaScript embedded injection system to abuse CloudFlare's standard human verification overlay rather than redirecting to a different landing page," Mouton explains. The payload also differs from most ClickFix campaigns, in which an infostealer is deployed on the victim's system that can be neutralized by blocking the attacker’s C2 server, cutting off communications with infected machines, he said. "This ClickFix campaign actually results in a dropper being run, which contacts a staging server that installs the C2 agent and persistence mechanism," Mouton explains. Overall, the novel tactics of the campaign suggest that the unidentified attacker is likely an initial access broker (IAB) rather than a typical ClickFix attacker, he adds. Related:15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning A Dual-Pronged 'Surprise' Attack There are two different types of victims in the campaign's attack vector: the business whose site is compromised to display the ClickFix lure and the individual who falls victim to the campaign, Mouton tells Dark Reading. Typically, the front-end business website gets compromised, which results in the malicious JavaScript getting embedded in their website's source code, he says. This compromise usually happens on a large scale, whether that is mass exploitation of a WordPress vulnerability or some other mechanism. "This first step occurs prior to initiating the campaign as a whole, though, during the infrastructure setup," Mouton explains. This is a similar approach used in other campaigns that have featuring EtherHiding; for example, digital ad security firm Confiant recently spotted a Magecart campaign that begins with compromised e-commerce sites on WooCommerce, Magento and WordPress. The next step would be the end-user who falls victim to what's become a now-familiar ClickFix lure by searching for a site that happens to be compromised. Then the JavaScript goes through a preliminary "gating" mechanism, which determines whether the victim gets to the next stage or not, Mouton says. Related:'Flying Eagle' Full-Service Mobile RAT Builder Wings Across China "If the victim gets through the gate, the 'Human Verification' mechanism appears as an overlay on the webpage that then produces the typical ClickFix lure, instructing the user to hit Windows+R, Ctrl+V, and then enter," he says. This is what initiates the malware dropper and thus the subsequent payload execution. As mentioned previously, that payload and the next step of the attack are notable deviations from a typical ClickFix campaign, and came as a surprise to the research team, Mouton says. By embedding a conventional C2 domain or IP address in the malware, the backdoor queries the Polygon blockchain for its current destination. "Our … team was engaged on what we thought was a standard BEC investigation, then we found a persistence script that reached out to the Polygon blockchain," he says. "After some de-obfuscation of the script and some extensive pivoting we discovered EtherHiding infrastructure." Attackers in the campaign use the blockchain as "an attacker-controlled address book: the malware can retrieve an updated C2 address without requiring the malware itself to change," Mouton wrote in the report. As a result, the the backdoor's installation shows no visible indication of compromise, and the malware survives reboots, beacons to C2 every minute, and retrieves updated instructions from the Polygon blockchain, he said. Human-Centric Defense Needed Researchers from Proofpoint first spotted ClickFix attacks about two years ago, and the technique has taken off with the cybercriminal community since then. The ultimate aim of the attack is to trick a user into executing malicious prompts against themselves. Though this campaign in particular puts a twist on this now-familiar tactic, the common denominator of the success of the campaign is ultimately human fallibility, Mouton explains. "Humans are well known to be the weakest link in most organizations," he says. To combat the campaign and others like it then, Mouton suggests introducing advanced phishing training to employees that includes the ability to recognize ClickFix and other social engineering tactics. This training should be combined with technological security measures as well, such as blocking avenues of querying any blockchain endpoints unless otherwise stated by business requirements, and implementing PowerShell logging where possible, with effective alerting to identify any potential malicious script usage. "Most enterprise employees have no need to query the blockchain from company controlled endpoints," Mouton explains. "Blocking the various RPC endpoints that are hardcoded into the PowerShell script would effectively sever this particular strain's ability to contact the C2." About the Author Elizabeth Montalbano Contributing Writer Elizabeth Montalbano is freelance writer, editor, and journalist with 30 years of professional experience and a master's degree from Arizona State University. Her areas of expertise include enterprise technology, cybersecurity, business, and culture. During her long career, Elizabeth has lived and worked as a full-time journalist in Phoenix, San Francisco, and New York City. She specializes in news coverage and analysis, using her years of experience to look at the current state of cybersecurity with a critical gaze. She currently resides in a village on the southwest coast of Portugal, where in her free time she enjoys surfing, hiking with her dogs, growing plants, and playing and performing as a singer and musician. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars Cloud Incident Response: Forensics in Distributed Environments Beyond the Login: Key Considerations for Evaluating Identity Security SASE Pivot and Trends 2026: A Gartner Keynote What Every Enterprise Should Know About Securing Cloud Assets In the Age of AI The Dos and Don'ts of a Cybersecurity Awareness Month People Actually Remember More Webinars You May Also Like ENDPOINT SECURITY Swipe, Plug-in, Pwned: Researchers Find New Ways to Hack Vehicles by Robert Lemos JAN 23, 2026 ENDPOINT SECURITY 2 Separate Campaigns Probe Corporate LLMs for Secrets by Elizabeth Montalbano JAN 12, 2026 ENDPOINT SECURITY Pro-Russian Hackers Use Linux VMs to Hide in Windows by Alexander Culafi NOV 04, 2025 ENDPOINT SECURITY Undead Operating Systems Haunt Enterprise Security Networks by Fahmida Y. Rashid OCT 01, 2025 Featured Check out the Black Hat USA 2026 Conference Guide for coverage and intel from — and about — the show! Editor's Choice CYBER RISK What We Missed: Delta Flight Disrupted With Wi-Fi Hack byRob Wright,Alexander Culafi AUG 20, 2026 CYBERATTACKS & DATA BREACHES Agentic AI Presents New Insider Threat Model for Orgs AUG 19, 2026 CYBERSECURITY OPERATIONS Mission-Driven Secur

Share this article