ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain

Summary

The ClickFix campaign has successfully compromised 31 organizations by exploiting the Polygon blockchain. Attackers are using a technique called EtherHiding to dynamically update their command-and-control servers, effectively using the blockchain as a disguised address book.

IFF Assessment

FOE

This campaign's success in compromising multiple organizations and its novel use of blockchain technology for C2 infrastructure represents a new threat vector for defenders to contend with.

Defender Context

Defenders should be aware of evolving attack techniques that leverage blockchain technology for C2 infrastructure. Monitoring for unusual blockchain activity or transactions that deviate from typical patterns may help detect such campaigns.

Read Full Story →