Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: c2-resilience (1 article)Clear

ClickFix campaign hides its command server on the Polygon blockchain

Researchers at GuidePoint found a ClickFix campaign that compromised at least 31 organizations' websites and abuses the Polygon blockchain to run its command-and-control, a technique called EtherHiding. Visitors arriving from search engines hit a fake human-verification prompt that abuses Cloudflare's overlay and tells them to paste a command, which installs a persistent backdoor. Instead of a fixed server address that defenders can block, the backdoor fetches its current instructions from a Polygon smart contract every minute, giving the attacker a censorship-resistant, easily updated address book. This breaks the usual defense of blocking a hardcoded command server, so defenders should focus on behavior and audit their public-facing sites.

Check
Teach users that no verification prompt should ask them to paste commands, audit public-facing websites for injected scripts, and hunt for backdoors that resolve command servers through blockchain queries.
Affected
Organizations whose websites are compromised to serve the fake verification lure, and users tricked into running the pasted command; the resulting backdoor persists and pulls updatable instructions from the blockchain.
Fix
Detect on behavior rather than static addresses, block or flag outbound blockchain-resolution queries from endpoints, monitor for domain-generation patterns, continuously audit websites for injected code, and train users against paste-a-command verification tricks.