ClickFix campaign hides its command server on the Polygon blockchain
Researchers at GuidePoint found a ClickFix campaign that compromised at least 31 organizations' websites and abuses the Polygon blockchain to run its command-and-control, a technique called EtherHiding. Visitors arriving from search engines hit a fake human-verification prompt that abuses Cloudflare's overlay and tells them to paste a command, which installs a persistent backdoor. Instead of a fixed server address that defenders can block, the backdoor fetches its current instructions from a Polygon smart contract every minute, giving the attacker a censorship-resistant, easily updated address book. This breaks the usual defense of blocking a hardcoded command server, so defenders should focus on behavior and audit their public-facing sites.
- Check
- Teach users that no verification prompt should ask them to paste commands, audit public-facing websites for injected scripts, and hunt for backdoors that resolve command servers through blockchain queries.
- Affected
- Organizations whose websites are compromised to serve the fake verification lure, and users tricked into running the pasted command; the resulting backdoor persists and pulls updatable instructions from the blockchain.
- Fix
- Detect on behavior rather than static addresses, block or flag outbound blockchain-resolution queries from endpoints, monitor for domain-generation patterns, continuously audit websites for injected code, and train users against paste-a-command verification tricks.