ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain
Refract AI Intelligence Digest
BLUF
Attackers are weaponizing blockchain technology to evade detection and maintain persistent access.
NEWS
The campaign utilized EtherHiding on the Polygon network to store command-and-control data across 31 compromised organizations. This approach enables dynamic server updates without relying on standard domain infrastructure.
Why I Care
Blockchain-based C2 bypasses conventional DNS filtering, significantly increasing the risk of undetected lateral movement and data theft in enterprise environments.
Next Steps
SOC teams should audit network logs for Polygon-related traffic and update detection rules to identify EtherHiding patterns within 48 hours.
The campaign uses EtherHiding to dynamically update its command-and-control server, abusing the blockchain as an attacker-controlled address book.
Source: Dark Reading ·