Over 5,400 Websites Compromised to Deliver ClickFix Payloads via Blockchain

Over 5,400 Websites Compromised to Deliver ClickFix Payloads via Blockchain

First seen 5 Sep 2026, 15:44 UTC Bleepingcomputerwww.netskope.com 67.5

Article Content

Browse articles
ThreatCluster

A cybercriminal operation has compromised over 5,400 small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). Most affected sites are built on WordPress and PrestaShop, with the initial compromise method still unknown. Each site has been injected with a script that retrieves the payload from a BSC Testnet endpoint, utilizing a technique called EtherHiding. The payload displays a fake CAPTCHA, instructing users to execute a PowerShell command that downloads malicious software. Researchers from Netskope report that the number of compromised sites has been steadily increasing, with over 300 sites active daily. A newer variant of the attack has replaced the ClickFix payload with a WebRTC data-channel stager, allowing attackers to establish covert communication with the victim's browser. The operation has shown a significant increase in activity since spring 2026, raising concerns for small businesses worldwide.

Key Points: • Over 5,400 small-business websites compromised to deliver malware via blockchain. • Attackers use EtherHiding to store malicious payloads in smart contracts on BSC Testnet. • New variants of the attack utilize WebRTC for covert command and control.

Ask AI about this cluster

Timeline

2026-09-05
Netskope reports on compromised websites
Netskope identified over 5,400 websites compromised to deliver ClickFix payloads via blockchain, with an increase in activity noted since spring.
Netskope
2026-09-05
BleepingComputer covers the attack
BleepingComputer reports on the massive cybercriminal operation leveraging compromised small-business websites to deliver malware.
BleepingComputer