ClickFix Campaign Abuses Polygon Blockchain to Evade Detection
A ClickFix campaign has exploited at least 31 organizations by abusing the Polygon blockchain to evade detection, according to research from GuidePoint Security's Research and Intelligence Team. The attackers used a technique called EtherHiding, which allows them to dynamically update their server locations for mere fractions of a cent per transaction, making traditional blocking methods ineffective.
The campaign begins by compromising legitimate business websites, embedding malicious JavaScript into their source code. Attackers often exploit WordPress vulnerabilities or similar mass-exploitation mechanisms to gain initial access. This setup phase occurs before the actual campaign launches and typically affects large-scale targets.
When a user searches for and visits a compromised site, the embedded JavaScript runs through a 'gating' mechanism to determine if the victim should proceed. If approved, a 'Human Verification' overlay appears on the webpage, mimicking a Cloudflare security check. The attacker abuses this legitimate-looking overlay to deliver the typical ClickFix lure, instructing users to press Windows+R, Ctrl+V, and Enter.
The malware beacons to its controller every minute and retrieves updated instructions directly from the Polygon blockchain. This allows attackers to redirect infected machines to a new command-and-control server automatically, making traditional blocking ineffective. The economics are straightforward: for fractions of a cent per blockchain transaction, the attacker can dynamically update their server locations without requiring code changes.