Cybercriminals Exploit Polygon Blockchain to Hide ClickFix Botnet, Compromising Over 30 Organizations
A new wave of malicious activity linked to the ClickFix campaign has been traced to at least 31 organizations, according to security researchers who first reported the findings. The attackers are leveraging the Polygon network, a layer‑2 scaling solution for Ethereum, to mask the infrastructure that controls the malware, making detection and takedown considerably harder.
ClickFix is a modular ransomware‑as‑a‑service kit that drops a payload capable of encrypting files, exfiltrating data, and establishing a persistent foothold. Victims typically notice encrypted files or ransom notes, but the underlying command‑and‑control (C2) traffic often blends in with normal network chatter, allowing the campaign to remain under the radar for weeks.
The campaign’s novelty lies in its use of a technique dubbed “EtherHiding.” Rather than hard‑coding C2 server addresses, the malware queries the Polygon blockchain for a list of attacker‑controlled wallet addresses that serve as a dynamic address book. Each address contains a small data payload pointing to the current C2 endpoint, enabling the operators to rotate servers instantly without altering the malware code. Because blockchain entries are immutable and publicly accessible, defenders cannot easily block the traffic without also disrupting legitimate blockchain activity.
Security analysts say the abuse of a public blockchain for malicious purposes represents a troubling escalation. By embedding C2 information in a decentralized ledger, the attackers sidestep traditional sink‑hole or IP‑blacklisting tactics. The 31 compromised entities span multiple industries, though specific sectors have not been disclosed, highlighting how the technique can be applied broadly regardless of target profile.
Researchers urge organizations to monitor outbound connections to cryptocurrency nodes, especially those interacting with Polygon, and to employ heuristic‑based detection that flags unusual query patterns to blockchain explorers. As blockchain adoption grows, defenders will need to develop new tools to differentiate legitimate decentralized traffic from covert malicious channels, a challenge that will likely shape cyber‑defense strategies in the months ahead.
Comments (0)
Be the first to comment.
Join the discussion