
highMalware
ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain
A threat actor campaign identified as ClickFix has compromised 31 organizations by abusing the Polygon blockchain. The campaign deploys EtherHiding malware, which uses blockchain transactions as a mechanism to dynamically update command-and-control (C2) server addresses. This technique allows the malware to evade traditional network-based blocking and maintain persistence. The abuse of the blockchain functions as an attacker-controlled address book, fetching updated C2 information. While the exact compromise methods and victim industry verticals remain under verification, the campaign represents a novel convergence of malware and decentralized ledger technology for malicious infrastructure management.
Dark reading1 min read