ClickFix Abuses Polygon Blockchain to Hide C2 Infrastructure Across 31 Orgs
The ClickFix campaign exploited the immutable and decentralized nature of the Polygon blockchain to store and rotate command-and-control server addresses using a technique called EtherHiding. Because blockchain transactions cannot be deleted or easily blocked at the source, traditional domain takedown and IP blacklisting defenses are rendered largely ineffective. This represents a significant evolution in attacker tradecraft, where legitimate public infrastructure is weaponized to evade detection and disruption. Organizations that rely solely on static threat intelligence feeds or domain-based blocking failed to detect or intercept the malicious traffic. The campaign's success across 31 organizations underscores a dangerous gap in awareness of emerging evasion techniques and the monitoring of outbound traffic to blockchain RPC endpoints.
Tactical Insight
Immediate actions
- Block or restrict outbound connections to public blockchain RPC endpoints (e.g., Polygon, Ethereum) at the perimeter firewall unless explicitly required by business operations.
- Hunt for indicators of compromise associated with ClickFix/EtherHiding across endpoint and network logs immediately.
- Deploy behavioral-based endpoint detection rules to flag unusual processes querying blockchain APIs or executing scripts from clipboard input.
Long-term improvements
- Implement application-layer inspection and egress filtering to detect and alert on anomalous outbound traffic patterns to decentralized web endpoints.
- Establish a threat intelligence program that tracks emerging C2 evasion techniques, including blockchain-based infrastructure abuse.
- Conduct regular red team exercises that simulate novel C2 channels to validate detection and response capabilities.
Detection measures
- Configure SIEM rules to alert on process executions or network calls originating from user-facing applications (browsers, office tools) that reach blockchain RPC URLs.
- Baseline and monitor DNS and HTTP traffic for connections to known Web3 providers (e.g., Infura, Alchemy, Polygon RPC nodes) from non-development endpoints.
- Enable user and entity behavior analytics (UEBA) to detect anomalous script execution patterns consistent with ClickFix-style clipboard hijacking lures.