ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain

Attackers have exploited a sophisticated campaign, dubbed ClickFix, compromising at least 31 organizations and leveraging the Polygon blockchain technology in a technique known as “EtherHiding” to obscure and automate malicious activity. This campaign has already targeted various businesses across e-commerce, professional services, and retail logistics sectors.

GuidePoint Security’s Research and Intelligence Team (GRIT) released a report detailing their findings on blockchain forensics, incident-response evidence, and analysis of the malware’s source code. According to GRIT, EtherHiding emerged several years ago as a technique that abuses blockchain technology to cover up malicious activity. In this case, attackers use the Polygon cryptocurrency blockchain to dynamically update their command-and-control (C2) servers, rather than using a fixed C2 server address which is more easily detected and blocked.

This approach differs from traditional ClickFix campaigns, where an infostealer is deployed on the victim’s system that can be neutralized by blocking the attacker’s C2 server. In this case, the attackers use EtherHiding to redirect every infected machine to a new C2 server automatically, allowing them to maintain control over their operations at a minimal cost – just fractions of a cent per transaction.

The ClickFix campaign also employs novel tactics, including using “a Search Engine Poisoning system and malicious JavaScript embedded injection system” to abuse CloudFlare’s standard human verification overlay. Furthermore, the payload is a dropper that contacts a staging server to install the C2 agent and persistence mechanism, rather than an infostealer.

The attackers’ goal is twofold: to compromise business websites to display the ClickFix lure and to infect individual users who fall victim to the campaign. Typically, this occurs on a large scale, often through mass exploitation of vulnerabilities in WordPress or other mechanisms. The compromised website becomes a front-end for the malicious activity, with the attackers using JavaScript to determine whether the user gets to the next stage.

The use of EtherHiding and the novelty of the ClickFix campaign’s tactics suggest that the unidentified attacker is likely an initial access broker (IAB) rather than a typical ClickFix attacker. This distinction highlights the evolving nature of cyber threats, where attackers are constantly adapting their techniques to evade detection.

As a result of this campaign, organizations must take extra precautions to protect themselves from similar attacks in the future. A key takeaway from this incident is that traditional security measures may not be enough to combat sophisticated threats like ClickFix. Organizations should consider implementing additional security controls, such as monitoring blockchain activity and blocking suspicious transactions, to stay ahead of these emerging threats.


Source: Dark Reading — 2026-09-01