www.netskope.com
Over 5,400 Websites Compromised to Deliver ClickFix Payloads via Blockchain
Article Content
A cybercriminal operation has compromised over 5,400 small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). Most affected sites are built on WordPress and PrestaShop, with the initial compromise method still unknown. Each site has been injected with a script that retrieves the payload from a BSC Testnet endpoint, utilizing a technique called EtherHiding. The payload displays a fake CAPTCHA, instructing users to execute a PowerShell command that downloads malicious software. Researchers from Netskope report that the number of compromised sites has been steadily increasing, with over 300 sites active daily. A newer variant of the attack has replaced the ClickFix payload with a WebRTC data-channel stager, allowing attackers to establish covert communication with the victim's browser. The operation has shown a significant increase in activity since spring 2026, raising concerns for small businesses worldwide.
Key Points: • Over 5,400 small-business websites compromised to deliver malware via blockchain. • Attackers use EtherHiding to store malicious payloads in smart contracts on BSC Testnet. • New variants of the attack utilize WebRTC for covert command and control.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.