ClickFix Campaign Exploits Polygon Blockchain for Widespread Malware Attacks
Researchers have discovered a ClickFix campaign that has compromised at least 31 organizations through the Polygon blockchain technology. The attackers use a technique known as 'EtherHiding' to obscure and automate their malicious activity.
The campaign targets businesses in e-commerce, professional services, and retail logistics, among others. According to GuidePoint Security's Research and Intelligence Team (GRIT), the attackers use the Polygon cryptocurrency blockchain to dynamically update their command-and-control (C2) servers rather than using a fixed C2 server address.
This technique allows the attackers to redirect infected machines to new C2 servers automatically, making it difficult for security teams to block them. The campaign is notable for its use of 'EtherHiding' on the Polygon blockchain, which is a departure from previous campaigns that used Binance or Ethereum.