THE ClickFix campaign has compromised at least 31 organizations by exploiting the Polygon blockchain with a technique known as 'EtherHiding,' which obscures and automates malicious activities. The attackers dynamically update command-and-control (C2) servers using the blockchain to avoid easy detection, unlike traditional C2 systems.
The campaign employs a dual-plan approach targeting both the compromised business sites and individual victims, embedding malicious JavaScript into websites to lure users into executing malware. Experts emphasize the need for enhanced employee training against phishing and implementing advanced security measures to block unnecessary blockchain queries from company endpoints.