ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain
ClickFix operators are weaponising Polygon smart contracts as a tamper-proof C2 address book, hitting 31 organisations—a technique that sidesteps domain takedowns and demands blockchain-aware detection.
Summary written by editorial AI · Source link below
The campaign uses EtherHiding to dynamically update its command-and-control server, abusing the blockchain as an attacker-controlled address book.
Editorial Analysis
Blockchain-hosted C2 infrastructure cannot be seized like traditional domains, forcing defenders to rethink takedown and blocking strategies.
Audit proxy and DNS logs for calls to public blockchain RPC endpoints and develop alert rules for EtherHiding-style C2 resolution.
Attackers are embedding command infrastructure in public blockchains, making traditional takedown approaches ineffective.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at Dark Reading in a new tab.
More from the Threat Intel Desk
- Attackers conceal phishing lures using invisible Unicode characters1d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication1d
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner1d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials2d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain2d