Attackers have compromised at least 31 organizations through a ClickFix campaign that abuses the Polygon blockchain technology in a technique known as "EtherHiding" to obscure and automate its malicious activity.
The campaign already has attacked the websites of various organizations, including businesses in e-commerce, professional services, and retail logistics, according to a report released today by GuidePoint Security's Research and Intelligence Team (GRIT). The report is based on GRIT's findings on blockchain forensics, incident-response evidence, and analysis of the malware's source code.
EtherHiding emerged several years ago as a technique that abuses blockchain technology to cover up malicious activity. In this case, the attackers use the Polygon cryptocurrency blockchain — a permanent, distributed ledger — to dynamically update their command-and-control (C2) servers rather than use a fixed C2 server address, which is more easily detected and blocked.
Related:'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month
"Because it allows for ad hoc adjustment of C2 details at scale, blocking a singular domain or IP address alone does not permanently sever attacker access," Jean-Pierre Mouton, senior threat intelligence consultant for GuidePoint, wrote in the report. "For fractions of a cent per transaction, the attacker can redirect every infected machine to a new C2 server automatically."
This differs from most ClickFix campaigns, in which an infostealer is deployed on the victim's system that can be neutralized by blocking the attacker's C2 server, cutting off communications with infected machines, he said.
ClickFix with Some Twists
To date, EtherHiding has been limited mostly to Binance or Etherium, Mouton tells Dark Reading. One thing that sets the campaign apart from others employing this tactic, then, is the use of Polygon smart contracts rather than those blockchain technologies, he says.
The attackers also put a new twist on ClickFix by using "a Search Engine Poisoning system and malicious JavaScript embedded injection system to abuse CloudFlare's standard human verification overlay rather than redirecting to a different landing page," Mouton explains.
The payload also differs from most ClickFix campaigns, in which an infostealer is deployed on the victim's system that can be neutralized by blocking the attacker’s C2 server, cutting off communications with infected machines, he said.
... continue reading