Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

Over 5,400 hacked sites deliver ClickFix payloads from blockchain

Researchers have identified more than 5,400 hacked websites, most built on WordPress and PrestaShop, being used to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC).

The sites contain scripts that retrieve the next-stage payload from a smart contract through a BSC Testnet endpoint. Netskope says this EtherHiding technique gives attackers infrastructure that is difficult to take down and lets them change the payload at any time.

The delivery chain shows a fake CAPTCHA that tells visitors to open the Windows Run dialog and paste a PowerShell command. That command downloads and executes the final payload.

Later in the campaign, the attackers replaced the ClickFix payload with a WebRTC data-channel stager. The stager creates a covert encrypted channel, receives JavaScript from a hardcoded command-and-control (C2) address, and executes the code in browser memory without saving it to disk. Netskope says the code runs when the channel closes or after 10 seconds.

The operation uses more than 300 infected websites every day. Nearly 400 websites called BSC Testnet RPC endpoints each day in August, with an all-time peak of 536. Netskope recommends blocking the listed BSC testnet RPC endpoints and monitoring for non-web UDP traffic associated with WebRTC.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.