ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain

**Sophisticated Attack Campaign Compromises 31 Organizations Using Abused Polygon Blockchain**

A highly sophisticated cyberattack campaign has compromised at least 31 organizations by abusing the Polygon blockchain technology. The ClickFix campaign uses a technique called “EtherHiding” to obscure and automate its malicious activity, making it challenging for security teams to detect and block.

The attackers behind this campaign have been using the Polygon cryptocurrency blockchain as an attacker-controlled address book, dynamically updating their command-and-control (C2) servers in real-time. This approach allows them to redirect infected machines to new C2 servers automatically, rendering traditional blocking methods ineffective. According to Jean-Pierre Mouton, senior threat intelligence consultant for GuidePoint Security’s Research and Intelligence Team (GRIT), this technique is a game-changer for attackers: “Because it allows for ad hoc adjustment of C2 details at scale, blocking a singular domain or IP address alone does not permanently sever attacker access.”

The campaign has already targeted various organizations across industries such as e-commerce, professional services, and retail logistics. The report by GRIT found that the attackers use a combination of techniques to compromise websites and infect end-users. This includes Search Engine Poisoning systems and malicious JavaScript embedded injection systems to abuse CloudFlare’s standard human verification overlay.

One unique aspect of this campaign is its use of Polygon smart contracts instead of Binance or Ethereum, which are more commonly associated with EtherHiding. The payload also differs from traditional ClickFix campaigns, deploying a dropper that contacts a staging server to install the C2 agent and persistence mechanism.

The novel tactics employed by this campaign suggest that the attacker may be an initial access broker (IAB) rather than a typical ClickFix attacker. This distinction is significant, as IABs often act as middlemen, providing attackers with unauthorized access to compromised systems. The campaign’s dual-pronged attack vector targets both business websites and individual users, making it a particularly insidious threat.

In light of this report, security teams should be aware of the evolving tactics used by cyberattackers. To mitigate these risks, organizations can take several steps:

* Regularly update software and plugins to prevent exploitation of vulnerabilities

* Implement robust security measures on websites, including CloudFlare’s human verification overlay

* Monitor for suspicious activity and block C2 servers in real-time

* Educate end-users about the importance of verifying website authenticity before entering sensitive information

By staying informed and vigilant, organizations can better protect themselves against these sophisticated attacks.


Source: Dark Reading — 2026-09-01