[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fyKGtfqStPKPRZ1ROTIbM-KPm2O6rUccy6NxCqsNpqD0":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":50},"2d130f7f-9ade-49f8-8b80-65c9fe4ef112","blockchain-hosted-clickfix-malware-hijacks-5400-websites","9adc0e18-5a1e-4847-b31a-416e72bbd70d","Blockchain-Hosted ClickFix Malware Hijacks 5,400+ Websites","Attackers compromised over 5,400 WordPress and PrestaShop sites — likely through unpatched plugins, weak credentials, or misconfigured admin panels — and injected malicious scripts that redirect visitors to fake CAPTCHA pages. The 'EtherHiding' technique stores malware payloads in BNB Smart Chain smart contracts, making traditional domain takedowns ineffective since the blockchain infrastructure cannot be simply seized or blocked. Victims are socially engineered into executing a malicious PowerShell command, bypassing endpoint defenses by abusing a trusted OS tool. This campaign highlights how attackers are chaining website compromise, decentralized infrastructure, and user manipulation to create highly resilient attack chains that evade conventional security controls.","**Immediate actions:**\n- Audit all internet-facing CMS platforms (WordPress, PrestaShop) for outdated plugins, themes, and core versions and apply patches immediately.\n- Scan compromised or suspect sites for unauthorized script injections and unknown JavaScript includes using a web application firewall or integrity checker.\n- Block or alert on unsanctioned PowerShell execution originating from browser processes via endpoint detection and response (EDR) rules.\n\n**Long-term improvements:**\n- Enforce a hardened CMS configuration baseline including least-privilege admin accounts, two-factor authentication, and file-integrity monitoring.\n- Implement Content Security Policy (CSP) headers on all web properties to restrict unauthorized script sources, including external blockchain RPC endpoints.\n- Establish a regular vulnerability management cycle with automated scanning of all web assets at least weekly.\n\n**Detection measures:**\n- Monitor outbound DNS and HTTP requests to known blockchain RPC nodes (e.g., BNB Smart Chain endpoints) from web servers and end-user workstations.\n- Deploy user-behavior analytics to flag unusual PowerShell or command-line activity spawned from browser or office application processes.\n- Train end users to recognize fake CAPTCHA and 'fix-it' social engineering prompts that request clipboard paste or terminal commands.",[12,13,14,15,16,17,18,19,20,21,22,23],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 7: Continuous Vulnerability Management","CIS Control 9: Email and Web Browser Protections","CIS Control 16: Application Software Security","NIST SP 800-53 SI-3: Malicious Code Protection","NIST SP 800-53 CM-6: Configuration Settings","NIST SP 800-53 RA-5: Vulnerability Monitoring and Scanning","NIST SP 800-53 AT-2: Literacy Training and Awareness","NIST CSF DE.CM-4: Malicious code detection","OWASP Top 10 A05: Security Misconfiguration","OWASP Top 10 A06: Vulnerable and Outdated Components","GDPR Article 32: Security of Processing (for EU site operators hosting user data)","published","2026-09-05T16:20:21.070798+00:00","2026-09-05T16:20:20.953+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fover-5-400-hacked-sites-serve-clickfix-payloads-stored-on-the-blockchain\u002F","over-5-400-hacked-sites-serve-clickfix-payloads-stored-on-the-blockchain-1305dd","Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain",[32,38,44],{"id":33,"name":34,"slug":35,"description":36,"color":37},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":39,"name":40,"slug":41,"description":42,"color":43},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":45,"name":46,"slug":47,"description":48,"color":49},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",[51],{"id":52,"date":53,"edition":54,"title":55,"audio_url":56},"4408bb8b-a8e5-4896-87d0-569646f6e051","2026-09-06","morning","ThreatNoir Weekend Brief — September 6","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-09-06\u002Fthreatnoir-morning-brief-2026-09-06.mp3"]