Threat Intelligence

Fake CAPTCHA Prompts Hide Malware in Blockchain-Powered Attack

Dark Reading · 1 Sept 2026
Key Takeaway Train staff to never copy and paste commands from websites or pop-ups claiming to verify you're human, and restrict the ability for regular users to run scripts on company devices.

A new attack campaign has compromised at least 31 organisations by tricking users into running malicious commands through fake verification prompts, a technique known as ClickFix. Victims are typically shown a bogus CAPTCHA or error message that instructs them to copy and paste a command into their computer, which then installs malware.

What makes this campaign notable is its use of a technique called EtherHiding, where attackers store and update their command-and-control instructions directly on the Polygon blockchain. Because blockchain transactions are decentralised and difficult to take down, this gives attackers a resilient, hard-to-block way of directing infected machines, effectively turning the blockchain into an attacker-controlled address book that can be updated at will.

This approach highlights how threat actors are adapting infrastructure to survive traditional takedown efforts used by security teams and law enforcement. Since the initial infection relies on tricking a person rather than exploiting a technical flaw, staff awareness remains a critical line of defence, alongside technical controls that restrict unnecessary command execution on business devices.

Summarised by CISO AI from Dark Reading. We link back to every original so you can read it yourself.