Hackers are using the Polygon blockchain to keep parts of a malware operation out of plain sight. The campaign, tracked as ErrTraffic, turns hacked WordPress sites into launch points for fake verification prompts that persuade visitors to run harmful Windows commands. The trick is known as ClickFix. Instead of exploiting a software flaw, the page tells a visitor to copy and paste a supposed fix, often into the Windows Run box or PowerShell.
That single action can download a payload, giving criminals access to browser data, saved credentials, cookies, and cryptocurrency-wallet information. The campaign matters because it mixes a convincing user prompt with infrastructure that can change quickly. WatchGuard said in a report that a compromised site may look normal until its injected code delivers the lure.[/subscribe_to_unlock_form]
Hackers are using the Polygon blockchain to keep parts of a malware operation out of plain sight. The campaign, tracked as ErrTraffic, turns hacked WordPress sites into launch points for fake verification prompts that persuade visitors to run harmful Windows commands. The trick is known as ClickFix. Instead of exploiting a software flaw, the page tells a visitor to copy and paste a supposed fix, often into the Windows Run box or PowerShell.
That single action can download a payload, giving criminals access to browser data, saved credentials, cookies, and cryptocurrency-wallet information. The campaign matters because it mixes a convincing user prompt with infrastructure that can change quickly. WatchGuard said in a report that a compromised site may look normal until its injected code delivers the lure.[emaillocker id="1283"]
Hackers Hide Malware Infrastructure on Polygon Blockchain. This practice, often called EtherHiding, makes takedowns harder because operators can update information held in the contract without revising every infected website. The approach pushes defenders beyond the web page, much like a WordPress traffic broker campaign.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1566.002 | Phishing | Spearphishing Link |
| Execution | T1059.001 | Command and Scripting Interpreter | PowerShell |
| Persistence | T1543.003 | Create or Modify System Process | Windows Service |
| Defence Evasion | T1036.005 | Masquerading | Match Legitimate Resource Name or Location |
| Credential access | T1555.003 | Credentials from Password Stores | Credentials from Web Browsers |
| Collection | T1005 | Data from Local System | - |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | - |
The following reports contain further technical details:
[/emaillocker]