ClickFix Campaign Uses Polygon to Update Malware Server Addresses

14-Sep-2026 Block Telegraph

ClickFix Campaign Uses Polygon to Update Malware Server Addresses

A ClickFix campaign compromised at least 31 organizations while using the Polygon blockchain to help malware find its command-and-control servers, according to GuidePoint Security research covered by Dark Reading on September 1, 2026. The technique, known as EtherHiding, treats blockchain smart contracts as an attacker-controlled address book. It lets infected systems retrieve a changed server address without needing a new version of the malware.

The finding concerns attackers’ use of blockchain infrastructure, not a reported breach of the Polygon protocol. Nor does it mean the malware is undetectable. GuidePoint’s point is narrower: blocking one command-and-control domain or IP address may not permanently cut off an attacker who can publish a replacement destination for the malware to retrieve.

A Compromised Website And A Deceptive Verification Prompt

GuidePoint’s Research and Intelligence Team drew on blockchain forensics, incident-response evidence and malware-source analysis. The affected organizations included businesses in e-commerce, professional services and retail logistics. The report distinguishes between a business whose website is compromised and an individual who encounters the malicious content there. The figure of at least 31 organizations should not be read as a count of individual infected computers.

According to Jean-Pierre Mouton, a senior threat intelligence consultant at GuidePoint, attackers embed malicious JavaScript in compromised business websites. Search-engine poisoning is also part of the campaign. A visitor reaching an affected page is assessed by a gating mechanism before a deceptive human-verification overlay appears. That overlay provides the ClickFix lure, persuading the visitor to execute a command presented as a step needed to continue.

The familiar-looking verification screen is part of the deception. Its resemblance to a Cloudflare check does not establish a compromise of Cloudflare itself. In this campaign, following the lure runs a dropper, which contacts a staging server. The staging server then installs a command-and-control agent and a persistence mechanism, according to Mouton’s account.

How Polygon Supplies A Changing Server Address

The installed backdoor queries Polygon to obtain its current command-and-control destination. Mouton describes the blockchain as an address book that the attacker controls: the address can change while the malware on the infected machine stays the same. This separates the server destination from a fixed address that defenders could otherwise block once.

Ethernet cables connected to network equipment
Illustrative network infrastructure, not equipment identified in the ClickFix campaign. Stock photo by Vladimir Srajber via Pexels.

Mouton said the attacker could redirect infected machines to a new server for fractions of a cent per transaction. The research also described a backdoor that survives reboots and beacons to its controller every minute. These are reported characteristics of the investigated malware, not evidence that every program using Polygon behaves this way or that every Polygon connection is malicious.

The team encountered the blockchain connection during what it initially believed was a standard business email compromise investigation. A persistence script reached out to Polygon; further analysis and investigation revealed the EtherHiding infrastructure. Mouton told Dark Reading that earlier EtherHiding activity had mostly involved Binance or Ethereum, making this campaign’s use of Polygon smart contracts a distinguishing feature.

What The Findings Establish About The Attacker

Mouton assessed the unidentified actor as likely an initial-access broker. That is an assessment, not a confirmed identity. The combination of a dropper, persistent access and a changing command destination differs from the more familiar ClickFix pattern he described, in which an information-stealing payload relies on a controller that defenders can block.

The source also discusses possible ways business websites can be compromised, including mass exploitation of a WordPress vulnerability or another mechanism. It does not identify a particular WordPress vulnerability used in these incidents. Its references to WooCommerce and Magento concern a separate Magecart campaign and should not be treated as a platform list for this ClickFix investigation.

Defenses Still Apply Before And After Infection

In Dark Reading’s account of the research, Mouton recommends employee training that specifically covers ClickFix and other social-engineering tactics. The initial deception remains important even though blockchain infrastructure appears later in the attack. Recognizing a page that asks a visitor to execute a supposed verification command can interrupt that earlier stage.

His technical recommendations include PowerShell logging with effective alerting for potentially malicious scripts. He also recommends restricting access to blockchain-query endpoints where business requirements permit. That qualification matters for organizations that legitimately use blockchain services; the recommendation is not an unconditional ban on all such traffic.

Mouton said blocking the specific RPC endpoints hardcoded into this strain’s PowerShell script would sever its route to the controller. That distinguishes a targeted defensive measure from blocking one replaceable server address. The reported lesson is that defenders need to understand how the malware obtains its destination, while still addressing the deceptive prompt and script execution that precede that communication.

Also read: Bank of America Sets S&P 500 Target at 7,800, Sees Just 2% Upside Over Next 12 Months
WHAT'S YOUR OPINION?
Related News