cognitive cybersecurity intelligence

News and Analysis

Search

Hackers Hide Malware Infrastructure on Polygon Blockchain and Trick Users Into Running It With ClickFix

Hackers Hide Malware Infrastructure on Polygon Blockchain and Trick Users Into Running It With ClickFix

Hackers are using the Polygon blockchain to keep parts of a malware operation out of plain sight.

The campaign, tracked as ErrTraffic, turns hacked WordPress sites into launch points for fake verification prompts that persuade visitors to run harmful Windows commands.

The trick is known as ClickFix. Instead of exploiting a software flaw, the page tells a visitor to copy and paste a supposed fix, often into the Windows Run box or PowerShell.

That single action can download a payload, giving criminals access to browser data, saved credentials, cookies, and cryptocurrency-wallet information.

WatchGuard analysts identified the activity in telemetry and linked it to an ErrTraffic malware-as-a-service operation advertised by a forum user known as LenAI.

The findings show one delivery service distributing several threats, including Vidar, Okobot, LegionLoader, OnionDrop-related payloads, and BabaDedaLoader.

Identification of websites hosting ErrTraffic (Source – WatchGuard)

The campaign matters because it mixes a convincing user prompt with infrastructure that can change quickly.

WatchGuard said in a report shared with Cyber Security News (CSN) that a compromised site may look normal until its injected code delivers the lure.

Hackers Hide Malware Infrastructure on Polygon Blockchain

ErrTraffic begins after someone reaches a compromised WordPress website. The injected JavaScript does not contain the final destination in clear text.

Instead, it queries Polygon through remote procedure call services, retrieves configuration from a smart contract, and uses that answer to locate current attacker-controlled infrastructure.

Network flow that initiates the infection (Source – WatchGuard)

This practice, often called EtherHiding, makes takedowns harder because operators can update information held in the contract without revising every infected website.

The approach pushes defenders beyond the web page, much like a WordPress traffic broker campaign. The lure then asks the user to complete a bogus browser or CAPTCHA-style check.

Its PowerShell command can fetch both a randomly named 7-Zip program and a randomly named payload, or download the payload directly. The victim therefore performs the execution step.

C2 used by Vidar on Telegram and Steam (Source – WatchGuard)

The framework combines traffic routing, location-based filtering, and blockchain-backed resolution. That design helps affiliates change delivery paths while keeping the same social-engineering formula.

Multiple payloads raise the stakes

The payload choice is especially serious. Vidar targets browser and wallet data and was seen communicating through a Telegram channel, a Steam profile, and a compromised Brazilian website.

One variant created remote threads in Chrome and Edge, an effort that may expose information held by those browsers. Other cases show attackers broadening their options after entry.

Okobot arrived through a ZIP archive containing Volume2 and a malicious DLL, then attempted to weaken Microsoft Defender settings and remove a protection around LSASS, a Windows process that holds sensitive login material.

The pattern echoes recent ClickFix MSI delivery attacks, where a prompt turns ordinary user interaction into malware execution.

Process tree of the steps performed in the Okobot campaign (Source – WatchGuard)

Researchers also found a malicious MSI with a Node.js backdoor that used Tor for command-and-control traffic, plus OnionDrop variants that hid behind legitimate programs through DLL side-loading.

One Go-based variant contacted infrastructure associated with LegionLoader, while another chain used Windows compilation tools to reach a BabaDedaLoader payload.

For defenders, the priority is to prevent the prompt from becoming execution. Users should never paste commands from a CAPTCHA, update notice, or support page into Run, Terminal, or PowerShell.

Administrators should promptly investigate WordPress sites that set the errtraffic_session cookie, review unexpected PowerShell downloads, and watch for suspicious browser process injection.

Security teams should also inspect network activity that reaches Polygon RPC services immediately after visits to compromised sites, and correlate it with unusual downloads or newly created DLLs.

Keeping web applications patched and removing injected scripts reduces the available launch points, a lesson also illustrated by malicious WordPress plugin activity.

The broader warning is that familiar platforms can be repurposed as hiding places.

Blockchain services, normal Windows utilities, browser processes, and trusted-looking sites each play a small role, but together they allow an operator to rotate infrastructure and deliver different malware with little warning.

Organizations that monitor the full chain, rather than a single malware name, will have a better chance of spotting the next variation.

Indicators of compromise (IoCs):-

TypeIndicatorDescriptionHTTP cookieerrtraffic_session=Header value associated with websites hosting ErrTrafficURL patternhxxps://<domain>/api/index.php?a=dl&token=<64-digit>&src=cloudflare&cb=<chrome\|edge\|firefox>&ref=https%3A%2F%2F<domain2>%2F&mode=<cloudflare\|recaptcha>ErrTraffic PowerShell download patternDomainequinixad[.]monsterErrTraffic-associated URL hostDomainlsikjsns[.]beerErrTraffic-associated URL hostDomainap7[.]supportly[.]auErrTraffic-associated URL hostDomainframesavecloudjs[.]beerErrTraffic-associated URL hostDomaingrovalstandard[.]monsterErrTraffic-associated URL hostDomainbootstrup-cdn-ns[.]beerErrTraffic-associated URL hostDomaindreff-nsdns[.]beerErrTraffic-associated URL hostDomainremoteshcontrol[.]comErrTraffic-associated URL hostDomainslndcdnclaud[.]beerErrTraffic-associated URL hostDomainkarenheil[.]monsterErrTraffic-associated URL hostDomainkyjpwnw[.]monsterErrTraffic-associated URL hostDomainmoonglide[.]monsterErrTraffic-associated URL hostDomainpohuimne[.]lolErrTraffic-associated URL hostDomaintravel-js-ns[.]beerErrTraffic-associated URL hostDomainverification-cdn-cloud[.]beerErrTraffic-associated URL hostDomainweb-safe[.]beerErrTraffic-associated URL hostDomainaccordtrucking[.]monsterErrTraffic-associated URL hostDomainadflow[.]monsterErrTraffic-associated URL hostDomainadtraffic[.]monsterErrTraffic-associated URL hostDomainadzeta[.]monsterErrTraffic-associated URL hostDomainanakondabob[.]clubErrTraffic-associated URL hostDomainbcncdncl-ns[.]beerErrTraffic-associated URL hostDomainbest-claudns-js[.]beerErrTraffic-associated URL hostDomainbiletors[.]cfdErrTraffic-associated URL hostDomaincoffeecincup[.]monsterErrTraffic-associated URL hostDomaindogesgroom[.]monsterErrTraffic-associated URL hostDomainetomoidomen[.]cfdErrTraffic-associated URL hostDomainexportearth[.]monsterErrTraffic-associated URL hostDomainganiballektor[.]cfdErrTraffic-associated URL hostDomainghdnsserverns[.]beerErrTraffic-associated URL hostDomainistile-c-cloud[.]beerErrTraffic-associated URL hostDomainjogosdecarrobr[.]monsterErrTraffic-associated URL hostDomainletsgomakemoneyoncaptcha[.]beerErrTraffic-associated URL hostDomainmerindashop[.]cyouErrTraffic-associated URL hostDomainmnepohui[.]sbsErrTraffic-associated URL hostDomainmnoskemp[.]beerErrTraffic-associated URL hostDomainmob[.]lanjut[.]inErrTraffic-associated URL hostDomainnetworksolutionson[.]sbsErrTraffic-associated URL hostDomainns-claude-js[.]beerErrTraffic-associated URL hostDomainnslsconscloud[.]beerErrTraffic-associated URL hostDomainoraxdata[.]monsterErrTraffic-associated URL hostDomainssns-cdn-ns[.]beerErrTraffic-associated URL hostDomaintotalads[.]monsterErrTraffic-associated URL hostDomainvhyip[.]monsterErrTraffic-associated URL hostDomainweb-protection[.]beerErrTraffic-associated URL hostDomainwebflare[.]beerErrTraffic-associated URL hostDomainyangdiet[.]monsterErrTraffic-associated URL hostDomaindtc[.]victorramarisimobiliaria[.]com[.]brVidar command-and-control hostTelegram channelci0iiifVidar command-and-control channelChrome extension IDefaidnbmnnnibpcajpcglclefindmkajAdobe Create PDF plug-in listener targeted by a Vidar variantDomainbigblower[.]clickHost contacted by a Vidar-related executableFile nametaskcollect.dllDLL downloaded after connection to bigblower[.]clickFile nameprotobuff.dllMalicious DLL sideloaded in the Okobot chainFile nameVolume2.zipArchive downloaded and extracted during Okobot activityFile nameVolume2.exeExecutable launched in the Okobot chainFile nametunupd.phpOkobot download endpoint file nameFile nametook.phpOkobot PowerShell follow-on endpoint file nameDomainlivewallpapers[.]cfdOkobot command-and-control hostFile namebootstrap.jsMalicious script embedded in the Node.js backdoor MSIFile nameCoreBridge.dllDLL launched by the Node.js backdoorFile namesqlite.dllMalicious DLL sideloaded by acrobroker.exeFile nameacrobroker.exeLegitimate executable abused for DLL sideloadingFile nameactive_desktop_render_x64.dllMalicious DLL associated with the ClipBanker variantFile nameAdobe.dllDLL containing ClipBanker-related behaviorIP address and URLhxxp://158[.]94[.]208[.]104/x7GkP2mQ9zL4/my_s[.]binBabaDedaLoader-related payload URLFile namemy_s.binBabaDedaLoader-related payload file

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world
The post Hackers Hide Malware Infrastructure on Polygon Blockchain and Trick Users Into Running It With ClickFix appeared first on Cyber Security News.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts