ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain

Refract AI Intelligence Digest

BLUF

Attackers are weaponizing blockchain technology to evade detection and maintain persistent access.

NEWS

The campaign utilized EtherHiding on the Polygon network to store command-and-control data across 31 compromised organizations. This approach enables dynamic server updates without relying on standard domain infrastructure.

Why I Care

Blockchain-based C2 bypasses conventional DNS filtering, significantly increasing the risk of undetected lateral movement and data theft in enterprise environments.

Next Steps

SOC teams should audit network logs for Polygon-related traffic and update detection rules to identify EtherHiding patterns within 48 hours.

The campaign uses EtherHiding to dynamically update its command-and-control server, abusing the blockchain as an attacker-controlled address book.
Back to Blog Listing

Source: Dark Reading ·

This digest was generated by Refract AI Collective to help the public sector security community stay informed.