1. Basic Information
Article Name: Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain
Publisher: BleepingComputer
Publication Date: 2026-09-05
Original Source: BleepingComputer
1. Basic Information Article Name: Over 5,400 hacked sites serve ClickFix payloads...
1. Basic Information
Article Name: Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain
Publisher: BleepingComputer
Publication Date: 2026-09-05
Original Source: BleepingComputer

Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain

Clickfix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain

ClickFix Campaigns Abuse Legitimate Services for Persistence

ClickFix moves into the browser and onto WebDAV, Cisco Talos finds - SiliconANGLE

Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones

TerminalFix looks like ClickFix, but delivers a very different payload

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads…

Hackers are abusing a Ghost CMS website flaw to serve fake Cloudflare verification pages that pressure users into infecting their…

Researcher analyzed 3,000 ClickFix payloads and found rotating wrappers plus a Downloads-folder method built to bypass AMSI.

A threat actor tracked as DriveSurge has been operating large-scale malware distribution campaigns using ClickFix and FakeUpdates…

Ghost CMS flaw CVE-2026-26980 enabled attacks on 700+ sites, injecting ClickFix malware through fake CAPTCHA pages.

1. Basic Information Article Title: ClickFix moves into the browser: Cryptocurrency...