Threat Advisory

ErrTraffic Campaign Uses Polygon Blockchain to Hide Malware Infrastructure

Threat: Malware
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Hackers are using the Polygon blockchain to keep parts of a malware operation out of plain sight. The campaign, tracked as ErrTraffic, turns hacked WordPress sites into launch points for fake verification prompts that persuade visitors to run harmful Windows commands. The trick is known as ClickFix. Instead of exploiting a software flaw, the page tells a visitor to copy and paste a supposed fix, often into the Windows Run box or PowerShell.

That single action can download a payload, giving criminals access to browser data, saved credentials, cookies, and cryptocurrency-wallet information. The campaign matters because it mixes a convincing user prompt with infrastructure that can change quickly. WatchGuard said in a report that a compromised site may look normal until its injected code delivers the lure.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Hackers are using the Polygon blockchain to keep parts of a malware operation out of plain sight. The campaign, tracked as ErrTraffic, turns hacked WordPress sites into launch points for fake verification prompts that persuade visitors to run harmful Windows commands. The trick is known as ClickFix. Instead of exploiting a software flaw, the page tells a visitor to copy and paste a supposed fix, often into the Windows Run box or PowerShell.

That single action can download a payload, giving criminals access to browser data, saved credentials, cookies, and cryptocurrency-wallet information. The campaign matters because it mixes a convincing user prompt with infrastructure that can change quickly. WatchGuard said in a report that a compromised site may look normal until its injected code delivers the lure.[emaillocker id="1283"]

Hackers Hide Malware Infrastructure on Polygon Blockchain. This practice, often called EtherHiding, makes takedowns harder because operators can update information held in the contract without revising every infected website. The approach pushes defenders beyond the web page, much like a WordPress traffic broker campaign.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1566.002 Phishing Spearphishing Link
Execution T1059.001 Command and Scripting Interpreter PowerShell
Persistence T1543.003 Create or Modify System Process Windows Service
Defence Evasion T1036.005 Masquerading Match Legitimate Resource Name or Location
Credential access T1555.003 Credentials from Password Stores Credentials from Web Browsers
Collection T1005 Data from Local System -
Command and control T1071.001 Application Layer Protocol Web Protocols
Exfiltration T1041 Exfiltration Over C2 Channel -

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu