Back to all lessons
Awareness Lessons
last month

ClickFix Abuses Polygon Blockchain to Hide C2 Infrastructure Across 31 Orgs

The ClickFix campaign exploited the immutable and decentralized nature of the Polygon blockchain to store and rotate command-and-control server addresses using a technique called EtherHiding. Because blockchain transactions cannot be deleted or easily blocked at the source, traditional domain takedown and IP blacklisting defenses are rendered largely ineffective. This represents a significant evolution in attacker tradecraft, where legitimate public infrastructure is weaponized to evade detection and disruption. Organizations that rely solely on static threat intelligence feeds or domain-based blocking failed to detect or intercept the malicious traffic. The campaign's success across 31 organizations underscores a dangerous gap in awareness of emerging evasion techniques and the monitoring of outbound traffic to blockchain RPC endpoints.

Tactical Insight

Immediate actions

  • Block or restrict outbound connections to public blockchain RPC endpoints (e.g., Polygon, Ethereum) at the perimeter firewall unless explicitly required by business operations.
  • Hunt for indicators of compromise associated with ClickFix/EtherHiding across endpoint and network logs immediately.
  • Deploy behavioral-based endpoint detection rules to flag unusual processes querying blockchain APIs or executing scripts from clipboard input.

Long-term improvements

  • Implement application-layer inspection and egress filtering to detect and alert on anomalous outbound traffic patterns to decentralized web endpoints.
  • Establish a threat intelligence program that tracks emerging C2 evasion techniques, including blockchain-based infrastructure abuse.
  • Conduct regular red team exercises that simulate novel C2 channels to validate detection and response capabilities.

Detection measures

  • Configure SIEM rules to alert on process executions or network calls originating from user-facing applications (browsers, office tools) that reach blockchain RPC URLs.
  • Baseline and monitor DNS and HTTP traffic for connections to known Web3 providers (e.g., Infura, Alchemy, Polygon RPC nodes) from non-development endpoints.
  • Enable user and entity behavior analytics (UEBA) to detect anomalous script execution patterns consistent with ClickFix-style clipboard hijacking lures.