ZeroHour
Dark Readingpublished ()ingested Elizabeth Montalbano

ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain

mediumThreat actor exploited in the wildimportance 60
AI summary · glm-5.3-flash

A ClickFix social engineering campaign compromised 31 organizations, abusing the Polygon blockchain via EtherHiding for dynamically updated command-and-control.

The campaign uses ClickFix-style social engineering to compromise victims, with 31 organizations affected. It employs EtherHiding to dynamically update its command-and-control server, abusing the Polygon blockchain as an attacker-controlled address book. This blockchain-based C2 approach makes the infrastructure more resilient and harder to take down.

  • 31 organizations compromised in the campaign
  • EtherHiding hosts C2 updates on the Polygon blockchain
  • Blockchain functions as an attacker-controlled address book for C2 resilience
  • ClickFix lures trick users into executing attacker-provided commands
ProductsPolygon
Full article

The campaign uses EtherHiding to dynamically update its command-and-control server, abusing the blockchain as an attacker-controlled address book.

This source does not provide full text. Read it at darkreading.com.