Established 2026Sunday, 6 September 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageThreat Intel Desk
Threat Intel

ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain

ClickFix operators are weaponising Polygon smart contracts as a tamper-proof C2 address book, hitting 31 organisations—a technique that sidesteps domain takedowns and demands blockchain-aware detection.

Summary written by editorial AI · Source link below

Filed by Dark Reading1 min readRead at source ↗

The campaign uses EtherHiding to dynamically update its command-and-control server, abusing the blockchain as an attacker-controlled address book.

Editorial Analysis

Why it matters

Blockchain-hosted C2 infrastructure cannot be seized like traditional domains, forcing defenders to rethink takedown and blocking strategies.

What to do

Audit proxy and DNS logs for calls to public blockchain RPC endpoints and develop alert rules for EtherHiding-style C2 resolution.

Board brief

Attackers are embedding command infrastructure in public blockchains, making traditional takedown approaches ineffective.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at Dark Reading

External link — opens at Dark Reading in a new tab.

§
Continue with

More from the Threat Intel Desk