CuraSec

Act active

5,400 Hacked Sites Deliver ClickFix Payloads via Blockchain Smart Contracts

2026-09-06 14:08 UTC · BleepingComputer · read the source ↗ #clickfix#supply-chain#malware-campaign
  • Engineer — Plan: If you manage any public-facing web properties, audit them for injected ClickFix loader scripts; the blockchain storage makes payload URLs resilient to takedown, so perimeter blocklists alone won’t suffice.
  • SOC/IR — Act: Active campaign at scale — tune detections for ClickFix behavior patterns: browser-spawned mshta or PowerShell, clipboard-manipulation sequences, and outbound calls to BNB Chain RPC endpoints from endpoints since this campaign began.
  • Leader — Learn: The use of blockchain smart contracts as an abuse-resistant payload store is a meaningful evasion evolution worth noting; no immediate leadership action needed unless an internal investigation reveals your web presence among the 5,400 compromised sites.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.