Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain
BLUF
Threat actors are exploiting immutable blockchain storage to persist malware delivery across thousands of hijacked small-business sites.
NEWS
Security researchers identified a campaign where 5,400+ hacked sites redirect visitors to ClickFix scams hosted on BNB Smart Chain smart contracts. Unlike traditional hosting, the malicious payloads are stored on-chain, making them difficult to takedown or block via standard domain blacklists. The operation primarily targets small businesses whose websites have been compromised to serve as infection vectors.
Why I Care
This matters because blockchain-based hosting evades traditional security controls and takedown requests, allowing the campaign to persist longer. Small business owners risk reputational damage and liability, while end-users face high-risk malware infections like infostealers or ransomware when visiting seemingly legitimate sites.
Next Steps
Website administrators should audit their sites for unauthorized redirects and update CMS plugins immediately. Security teams must monitor for ClickFix indicators of compromise and educate users to never copy-paste commands from web prompts. Organizations should implement DNS filtering that blocks known malicious blockchain domains starting today.
Source: BleepingComputer ·