Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
US SOCs Combat Alert Fatigue: Strategies for Cybersecurity Noise Reduction
August 11, 2026
Critical Windows PnP Vulnerability Lets Attackers Gain SYSTEM Access
August 11, 2026
ClickFix Users Exposed to Malware via Polygon Blockchain Infrastructure
August 11, 2026
Home/Threats/ClickFix Users Exposed to Malware via Polygon Blockchain Infrastructure
Threats

ClickFix Users Exposed to Malware via Polygon Blockchain Infrastructure

Key Takeaways A malware campaign, dubbed “ErrTraffic,” is leveraging the Polygon blockchain to conceal its command-and-control infrastructure. The attack chain, known as ClickFix, tricks...

Emy Elsamnoudy
Emy Elsamnoudy
August 11, 2026 5 Min Read
3 0

Key Takeaways

  • A malware campaign, dubbed “ErrTraffic,” is leveraging the Polygon blockchain to conceal its command-and-control infrastructure.
  • The attack chain, known as ClickFix, tricks users into executing malicious Windows commands through deceptive prompts on compromised WordPress sites.
  • Victims who fall for the ruse risk exposing sensitive data, including browser information, saved credentials, cookies, and cryptocurrency wallet details.
  • The campaign distributes multiple potent payloads, such as Vidar, Okobot, LegionLoader, OnionDrop-related malware, and BabaDedaLoader.
  • Defenders must prioritize user education against executing untrusted commands and implement robust monitoring for blockchain interactions and unusual system activity.

Cybersecurity researchers have uncovered a sophisticated malware operation, designated ErrTraffic, that cleverly utilizes the Polygon blockchain to obscure its critical infrastructure. This innovative tactic allows threat actors to maintain persistence and agility, making detection and takedown efforts significantly more challenging.

Table Of Content

  • Key Takeaways
  • The ClickFix Deception and its Consequences
  • Hackers Hide Malware Infrastructure on Polygon Blockchain
  • Multiple Payloads Raise the Stakes
  • What You Should Do

The campaign employs a social engineering technique known as ClickFix. Instead of exploiting software vulnerabilities, it manipulates users into manually executing malicious commands. This method is delivered via compromised WordPress websites, which serve as initial infection points.

The ClickFix Deception and its Consequences

Upon visiting a compromised WordPress site, users are presented with convincing, fake verification prompts. These lures instruct visitors to copy and paste purported “fixes” into Windows system interfaces like the Run box or PowerShell. This seemingly innocuous action is, in fact, the critical step that downloads a malicious payload onto the victim’s system.

Once executed, this payload grants attackers unauthorized access to a wealth of sensitive information. This includes browser data, stored credentials, cookies, and cryptocurrency wallet details, posing a severe risk of financial and data theft.

Analysts at WatchGuard identified this activity within their telemetry, linking it directly to an ErrTraffic malware-as-a-service operation. This service is reportedly advertised by a forum user known as LenAI. Their findings reveal a single delivery mechanism capable of distributing a diverse array of threats, including Vidar, Okobot, LegionLoader, various OnionDrop-related payloads, and BabaDedaLoader.

The efficacy of this campaign stems from its combination of persuasive social engineering and a highly adaptable infrastructure. As WatchGuard said in a report, a compromised website can appear entirely normal until its injected code delivers the deceptive prompt. This stealthy approach ensures a high success rate for initial compromise.

Hackers Hide Malware Infrastructure on Polygon Blockchain

The ErrTraffic attack chain initiates when a user lands on an infected WordPress site. The JavaScript injected into the site does not directly reveal the final malware destination. Instead, it queries the Polygon blockchain via remote procedure call (RPC) services. From a smart contract on Polygon, it retrieves configuration data that points to the current, attacker-controlled infrastructure.

This technique, often referred to as EtherHiding, significantly complicates efforts to dismantle the malware’s infrastructure. By storing critical command-and-control (C2) information on the blockchain, operators can rapidly update their infrastructure details within the smart contract without needing to modify every compromised website. This forces defenders to look beyond the immediate web page for indicators of compromise, mirroring challenges seen in other advanced traffic broker campaigns.

After retrieving the C2 information, the lure prompts the user to complete a fake browser or CAPTCHA-style check. The PowerShell command provided by the attackers can either download a randomly named 7-Zip program along with a randomly named payload, or directly fetch the payload. In either scenario, the victim is tricked into performing the execution step, thereby installing the malware.

The entire framework leverages traffic routing, location-based filtering, and blockchain-backed resolution. This sophisticated design enables affiliates to frequently alter their delivery paths while maintaining the same effective social engineering tactics.

Multiple Payloads Raise the Stakes

The variety and potency of the payloads distributed by ErrTraffic are particularly concerning. Vidar, for instance, is an information stealer designed to exfiltrate browser data and cryptocurrency wallet information. It has been observed communicating with its C2 servers through Telegram channels, Steam profiles, and even a compromised Brazilian website. One variant of Vidar was noted for creating remote threads within Chrome and Edge, potentially exposing sensitive data from these browsers.

Other instances demonstrate the attackers’ ability to diversify their post-compromise activities. The Okobot malware, for example, was delivered via a ZIP archive containing Volume2 and a malicious DLL. It then attempted to disable Microsoft Defender settings and remove protections around LSASS, a critical Windows process that holds sensitive login credentials. This pattern is reminiscent of recent ClickFix MSI delivery attacks, where a deceptive prompt transforms routine user interaction into malware execution.

Researchers also discovered a malicious MSI package containing a Node.js backdoor that utilized Tor for its command-and-control communications. Furthermore, variants of OnionDrop were found hiding behind legitimate programs through DLL side-loading. One particular Go-based variant connected to infrastructure associated with LegionLoader, while another infection chain employed Windows compilation tools to ultimately deliver a BabaDedaLoader payload.

What You Should Do

  • Educate Users: Emphasize to all users that they should never copy and paste commands from unexpected browser prompts, CAPTCHA requests, update notices, or support pages into Windows Run, Terminal, or PowerShell. Legitimate software updates or fixes will typically install through official installers, not manual command execution.
  • Monitor WordPress Sites: Administrators should vigilantly monitor WordPress sites for the presence of the errtraffic_session cookie. Any unexpected appearance of this cookie warrants immediate investigation.
  • Review PowerShell Activity: Implement logging and monitoring for PowerShell commands, particularly those involving unusual downloads or script executions. Investigate any PowerShell activity that retrieves files from suspicious or unknown sources.
  • Detect Browser Process Injection: Look for signs of suspicious process injection into legitimate browser processes (e.g., Chrome, Edge, Firefox). This could indicate the presence of info-stealing malware like Vidar.
  • Inspect Network Traffic: Specifically monitor network activity that attempts to reach Polygon RPC services immediately after visits to any potentially compromised websites. Correlate this with any unusual file downloads or the creation of new DLLs on endpoint systems.
  • Patch and Secure Web Applications: Ensure all web applications, especially WordPress installations and their plugins, are kept up-to-date with the latest security patches to mitigate injection vulnerabilities. Regularly audit websites for unauthorized injected scripts.
  • Comprehensive Threat Monitoring: Adopt a holistic approach to threat detection, focusing on monitoring the entire kill chain rather than isolating individual malware names. This includes observing traffic routing, location-based filtering, and blockchain interactions to identify evolving attack patterns.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitHackerMalwarePatchSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Critical FortiGate RCE CVE-2022-42475 Exploited in Polish Energy Sector Attack

Next Post

Critical Windows PnP Vulnerability Lets Attackers Gain SYSTEM Access

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Horizon3.ai Secures $20M to Boost Partner-Led Growth and Ecosystem
August 11, 2026
Chinese Hackers Use Fake DeepSeek Page to Deliver Malware
August 11, 2026
Critical LiteLLM Supply Chain Flaw Exposes 2,500 Companies, 434,000 CI/CD Pipelines
August 11, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us