Polygon Blockchain Used to Conceal Malware Infrastructure
Cybersecurity researchers have uncovered a malware campaign that uses the Polygon blockchain to conceal parts of its infrastructure, making it harder for attackers to disrupt their delivery network. The campaign, known as ErrTraffic, compromises WordPress websites and turns them into launch points for fake verification pages.
The technique, called ClickFix, relies on social engineering rather than exploiting a software vulnerability. Once a victim follows the instructions and runs the command, malware can be downloaded onto the system, potentially gaining access to browser information, stored credentials, cookies, and cryptocurrency wallet data.
The campaign combines convincing user interaction with blockchain-backed infrastructure, allowing attackers to change delivery details without modifying every compromised website. The Polygon Smart Contracts help conceal infrastructure by communicating with remote procedure call services and retrieving configuration information stored in a smart contract.
The infrastructure also incorporates traffic routing and location-based filtering, giving operators flexibility in deciding which visitors receive the malicious content. Multiple malware families are delivered through the campaign, including Vidar, Okobot, LegionLoader, OnionDrop-related payloads, and BabaDedaLoader.