ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain
AI summary · glm-5.3-flash
A ClickFix social engineering campaign compromised 31 organizations, abusing the Polygon blockchain via EtherHiding for dynamically updated command-and-control.
The campaign uses ClickFix-style social engineering to compromise victims, with 31 organizations affected. It employs EtherHiding to dynamically update its command-and-control server, abusing the Polygon blockchain as an attacker-controlled address book. This blockchain-based C2 approach makes the infrastructure more resilient and harder to take down.
- 31 organizations compromised in the campaign
- EtherHiding hosts C2 updates on the Polygon blockchain
- Blockchain functions as an attacker-controlled address book for C2 resilience
- ClickFix lures trick users into executing attacker-provided commands
ProductsPolygon
Full article
The campaign uses EtherHiding to dynamically update its command-and-control server, abusing the blockchain as an attacker-controlled address book.
This source does not provide full text. Read it at darkreading.com.