← Back to Feed
ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain
September 1, 2026 · Dark Reading · Severity: MEDIUM
The campaign uses EtherHiding to dynamically update its command-and-control server, abusing the blockchain as an attacker-controlled address book.
Key Takeaways
- The ClickFix campaign compromised 31 organizations using the EtherHiding technique.
- Attackers abuse the Polygon blockchain to dynamically update command-and-control servers.
- The blockchain serves as an attacker-controlled address book for persistent C2 communication.