Back to all lessons
Awareness Lessons
last month

Blockchain-Hosted ClickFix Malware Hijacks 5,400+ Websites

Attackers compromised over 5,400 WordPress and PrestaShop sites — likely through unpatched plugins, weak credentials, or misconfigured admin panels — and injected malicious scripts that redirect visitors to fake CAPTCHA pages. The 'EtherHiding' technique stores malware payloads in BNB Smart Chain smart contracts, making traditional domain takedowns ineffective since the blockchain infrastructure cannot be simply seized or blocked. Victims are socially engineered into executing a malicious PowerShell command, bypassing endpoint defenses by abusing a trusted OS tool. This campaign highlights how attackers are chaining website compromise, decentralized infrastructure, and user manipulation to create highly resilient attack chains that evade conventional security controls.

Tactical Insight

Immediate actions

  • Audit all internet-facing CMS platforms (WordPress, PrestaShop) for outdated plugins, themes, and core versions and apply patches immediately.
  • Scan compromised or suspect sites for unauthorized script injections and unknown JavaScript includes using a web application firewall or integrity checker.
  • Block or alert on unsanctioned PowerShell execution originating from browser processes via endpoint detection and response (EDR) rules.

Long-term improvements

  • Enforce a hardened CMS configuration baseline including least-privilege admin accounts, two-factor authentication, and file-integrity monitoring.
  • Implement Content Security Policy (CSP) headers on all web properties to restrict unauthorized script sources, including external blockchain RPC endpoints.
  • Establish a regular vulnerability management cycle with automated scanning of all web assets at least weekly.

Detection measures

  • Monitor outbound DNS and HTTP requests to known blockchain RPC nodes (e.g., BNB Smart Chain endpoints) from web servers and end-user workstations.
  • Deploy user-behavior analytics to flag unusual PowerShell or command-line activity spawned from browser or office application processes.
  • Train end users to recognize fake CAPTCHA and 'fix-it' social engineering prompts that request clipboard paste or terminal commands.