The campaign uses EtherHiding to dynamically update its command-and-control server, abusing the blockchain as an attacker-controlled address book.

September 1, 2026

Attackers have compromised at least 31 organizations through a ClickFix campaign that abuses the Polygon blockchain technology in a technique known as "EtherHiding" to obscure and automate its malicious activity.

The campaign already has attacked the websites of various organizations, including businesses in e-commerce, professional services, and retail logistics, according to a report released today by GuidePoint Security's Research and Intelligence Team (GRIT). The report is based on GRIT's findings on blockchain forensics, incident-response evidence, and analysis of the malware's source code.

EtherHiding emerged several years ago as a technique that abuses blockchain technology to cover up malicious activity. In this case, the attackers use the Polygon cryptocurrency blockchain — a permanent, distributed ledger — to dynamically update their command-and-control (C2) servers rather than use a fixed C2 server address, which is more easily detected and blocked.