A new wave of ClickFix malvertising attacks is chaining slick browser βfixβ prompts with an EtherHiding command-and-control layer that lives on the Polygon blockchain, giving attackers takedown-resistant infrastructure and quietly compromising organizations across multiple sectors[1][3][9][15]. Early incident-response telemetry points to several dozen victims worldwide, with some investigations estimating around thirty impacted environments, though the true scope remains unclear[1][11][15].
ClickFix is the social engineering engine at the front of these campaigns: victims are funneled to compromised WordPress or small-business sites that display fake CAPTCHA challenges or urgent update dialogs, then pressured to click through and run a βfixβ script or installer[1][10][15]. Once a user complies, injected JavaScript or a downloaded loader pivots to second-stage malware such as GULoader on Windows, AMOS (Atomic macOS Stealer) on macOS, or commodity stealers and loaders including Vidar, Okobot, LegionLoader, OnionDrop-linked payloads, and BabaDedaLoader[3][10][15]. Researchers describe the result as a full-stack intrusion chain that begins with a single search click and ends with credential theft, crypto-drain operations, and persistent access to infected endpoints[3][4][12].
The distinguishing feature of the latest ClickFix operations is EtherHiding, a technique that stores attacker configuration or C2 locations inside blockchain smart contracts instead of traditional domains or IP addresses[1][2][11]. In Polygon-backed variants, the malware or injected script issues read-only JSON-RPC calls such as eth_call to public RPC providers, retrieving an encoded C2 domain or payload URL from a contract controlled by the threat actor[1][3][9]. Analysis of one Polygon contract used in a ClickFix campaign found more than one hundred βSet URLβ updates rotating across nearly a hundred unique C2 domains over several months, all signed by the same wallet, underscoring how easily attackers can refresh their infrastructure without changing the malware itself[3][9]. Similar EtherHiding patterns have appeared on BNB Smart Chain and Ethereum, in crimeware and ransomware operations such as the ErrTraffic-based ClickFix attacks and the DeadLock ransomware family[6][13][15].
In one case study, investigators traced a live ClickFix incident to a compromised WordPress site whose robots.txt file had been weaponized with an embedded malicious script[1][13]. When visited, that script silently queried a Polygon smart contract to fetch the current second-stage C2 endpoint, then redirected the victimβs browser toward the next payload server[1][3][7]. Other reports describe WordPress mu-plugin backdoors that inject obfuscated JavaScript, which in turn reaches out to BNB Smart Chain testnet contracts to resolve multi-stage payload locations, allowing attackers to stage social engineering, loaders, and botnet components off infrastructure that cannot be seized or deleted[10][13][14]. Across these incidents, EtherHiding acts as an attacker-controlled address book, decoupling the visible victim-facing infrastructure from the configuration that steers where the campaign goes next[11][13][15].
Defenders face two major challenges: first, blockchain-backed C2 erodes the effectiveness of indicator-based detection, since domains and IPs can be rotated rapidly while the on-chain configuration remains a stable reference point[1][8][11]. Second, the infrastructure is both immutable and widely accessible; once a malicious contract is deployed, it cannot be removed via abuse reports, and the RPC calls often blend into trusted traffic routed through providers like Cloudflare or major Web3 gateways[3][6][10]. Security teams investigating ClickFix intrusions have instead focused on behavioral signals, including unexpected blockchain RPC traffic originating from user workstations or web servers, macOS Launch Agent persistence tied to stealer payloads, base64-encoded execution chains, and unusual WordPress plugins or file changes such as altered robots.txt or hidden mu-plugins[3][5][12].
So far, researchers emphasize that these campaigns primarily exploit weak site security and user trust rather than a single, well-defined software flaw, and no specific CVE has been universally linked to the current ClickFix EtherHiding waves[1][11][13]. Organizations are urged to harden and monitor their web properties, especially WordPress installations, deploy detection content for known ClickFix and EtherHiding artifacts, and instrument network monitoring to flag unexpected calls to public blockchain RPC endpoints from enterprise assets[3][11][15]. Endpoint defenses should treat fake CAPTCHA pages, unsolicited βupdateβ prompts, and browser-based commands as high-risk flows, subjecting any follow-on downloads or scripts to strict controls and sandboxing, particularly on macOS and Windows fleets that have been repeatedly targeted by the crimekits behind these campaigns[3][4][12].
References
- Cribl SecOps uncovers EtherHiding malware campaign on …
- Forensic Analysis of Etherhiding in ClickFix Campaign
- AMOS Stealer + XMRig macOS ClickFix Crimekit: EtherHiding C2 on Polygon Blockchain β OTX Detection Pack
- ClickFix Campaign Uses EtherHiding to Hide Malware and Exposes …
- Inside a ClickFix Attack: How VeiloVPN Hid C2 on Polygon
- DeadLock Ransomware Hides C2 on Polygon Blockchain, 80-Plus Victims Hit
- EtherHiding Attack Hides ClickFix Payload Infrastructure Inside Polygon Blockchain
- GitHub Repo Poisoning: SmartLoader Abuses AI & Utility …
- ClickFix 2026: Fake CAPTCHA Hides C2 On-Chain | PhishEye
- ClickFix Campaign Uses EtherHiding and GULoader to Infect Windows Users via Fake CAPTCHA
- Inside a Live ClickFix Campaign using EtherHiding to Hide …
- EtherHiding Malware on macOS: How Attackers Hide C2 …
- ErrTraffic v3 Uses EtherHiding in ClickFix Attacks
- The Bot Panel
- ErrTraffic Malware Campaign: ClickFix and EtherHiding | WatchGuard Technologies
