Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain

Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain
A large criminal campaign is using more than 5,400 compromised WordPress and PrestaShop websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain via EtherHiding. The operation has evolved to use a WebRTC-based stager and is contacting BSC Testnet RPC endpoints at scale, making the infrastructure harder to disrupt. #BNBSmartChain #EtherHiding #ClickFix #WordPress #PrestaShop

Keypoints

  • More than 5,400 compromised websites are part of the campaign.
  • Most infected sites are built on WordPress and PrestaShop.
  • The attackers use EtherHiding to store payloads in BSC smart contracts.
  • Visitors are shown a fake CAPTCHA that leads to a malicious PowerShell command.
  • The campaign now uses a WebRTC stager and hits BSC Testnet endpoints daily.

Read More: https://www.bleepingcomputer.com/news/security/over-5-400-hacked-sites-serve-clickfix-payloads-stored-on-the-blockchain/