Fake CAPTCHA Prompts Hide Malware in Blockchain-Powered Attack
A new attack campaign has compromised at least 31 organisations by tricking users into running malicious commands through fake verification prompts, a technique known as ClickFix. Victims are typically shown a bogus CAPTCHA or error message that instructs them to copy and paste a command into their computer, which then installs malware.
What makes this campaign notable is its use of a technique called EtherHiding, where attackers store and update their command-and-control instructions directly on the Polygon blockchain. Because blockchain transactions are decentralised and difficult to take down, this gives attackers a resilient, hard-to-block way of directing infected machines, effectively turning the blockchain into an attacker-controlled address book that can be updated at will.
This approach highlights how threat actors are adapting infrastructure to survive traditional takedown efforts used by security teams and law enforcement. Since the initial infection relies on tricking a person rather than exploiting a technical flaw, staff awareness remains a critical line of defence, alongside technical controls that restrict unnecessary command execution on business devices.