Advertise
CoinTrust
BTC
ETH
BCH
SOL
DOGE
SHIB
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
No Result
View All Result

Home » Hackers Hide Malware Infrastructure on Polygon Blockchain

Hackers Hide Malware Infrastructure on Polygon Blockchain

ClickFix Campaign Uses Compromised WordPress Sites

Kelly Cromley by Kelly Cromley
Aug 12, 2026
in Market News, News
Reading Time: 3 mins read
0
Malware

Cybersecurity researchers have uncovered a malware campaign that uses the Polygon blockchain to conceal parts of its infrastructure, allowing attackers to make their delivery network more difficult to disrupt.

The campaign, tracked as ErrTraffic, compromises WordPress websites and turns them into launch points for fake verification pages. Visitors are presented with prompts resembling browser checks or CAPTCHA procedures and are persuaded to execute Windows commands themselves. The technique, known as ClickFix, relies on social engineering rather than exploiting a software vulnerability.

Once a victim follows the instructions and runs the command, malware can be downloaded onto the system. Depending on the payload, attackers may gain access to browser information, stored credentials, cookies, and cryptocurrency wallet data.

WatchGuard analysts identified the activity through their telemetry and connected it to an ErrTraffic malware-as-a-service operation promoted by a forum user operating under the name LenAI. The infrastructure was found to distribute several malware families, including Vidar, Okobot, LegionLoader, OnionDrop-related payloads and BabaDedaLoader.

The campaign combines a convincing user interaction with blockchain-backed infrastructure, allowing attackers to change delivery details without modifying every compromised website.

Polygon Smart Contracts Help Conceal Infrastructure

The campaign begins when a visitor accesses an infected WordPress website. Malicious JavaScript injected into the page does not openly reveal the attacker’s final destination. Instead, it communicates with Polygon through remote procedure call services and retrieves configuration information stored in a smart contract.

That information is then used to identify the current attacker-controlled infrastructure. The technique, commonly referred to as EtherHiding, can complicate takedown efforts because attackers can modify information stored in the blockchain without having to update the malicious code placed on every infected website.

The infrastructure also incorporates traffic routing and location-based filtering, giving operators greater flexibility in deciding which visitors receive the malicious content. The resulting setup can allow different affiliates or operators to change delivery paths while maintaining the same basic social-engineering strategy.

The final PowerShell command may download a randomly named 7-Zip executable together with a similarly randomized payload or retrieve the malicious payload directly. This approach makes the victim responsible for the execution step while the attacker avoids relying solely on traditional software vulnerabilities.

Multiple Malware Families Increase the Risk

The range of malware delivered through the campaign adds to the threat. Vidar, for example, can target browser and cryptocurrency wallet information. Researchers observed versions communicating through services including Telegram, Steam and a compromised Brazilian website.

Another Vidar variant was observed creating remote threads inside Chrome and Edge processes, potentially allowing attackers to access information maintained by those browsers.

Okobot was also identified in the campaign. It arrived through a ZIP archive containing a file named Volume2 and a malicious DLL. Researchers found that the malware attempted to weaken Microsoft Defender protections and interfere with security mechanisms surrounding LSASS, a Windows process that manages sensitive authentication information.

Other components included a malicious MSI package containing a Node.js backdoor that used Tor for command-and-control communications. Researchers also identified OnionDrop variants that used DLL side-loading to conceal malicious activity behind legitimate applications.

Additional infection chains were associated with LegionLoader and BabaDedaLoader, demonstrating that the infrastructure could support multiple malware families rather than a single threat.

Defenders Urged to Monitor the Entire Attack Chain

Security teams should focus on preventing fake verification prompts from becoming execution points and should investigate suspicious PowerShell activity, browser process injection, and unusual downloads following visits to compromised websites.

Organizations can also look for WordPress sites that create the errtraffic_session cookie and examine network connections to Polygon RPC services that occur immediately after visits to suspicious pages. Newly created DLL files and unexpected downloads can provide additional indicators of compromise.

Keeping WordPress installations, plugins, and themes updated, while removing injected scripts, can reduce the number of websites available to attackers.

The campaign highlights a broader shift in cybercrime tactics in which legitimate technologies are repurposed to conceal malicious operations. Blockchain infrastructure, Windows utilities, browser processes, and trusted websites can each serve a limited function within an attack, but their combination can make the overall operation harder to identify and disrupt.

Monitoring the complete infection chain instead of focusing on a single malware family could give organizations a better chance of detecting future variations of the ErrTraffic campaign.

Previous Post

Broadridge Blockchain Repo Platform Hits $8 Trillion in July

Next Post

Russia Approves Bitcoin, Ethereum and USDT Trading, Excludes XRP

Related Posts

India

India’s NSDL Launches Blockchain Platform for Tokenized Bonds

by Kelly Cromley
Sep 13, 2026
0

India’s National Securities Depository Limited (NSDL) has launched Demat 2.0, a blockchain-based platform designed to support tokenized securities and enable...

Sei Labs

Sei Labs Acquires Bilinear Labs to Boost Blockchain Infrastructure

by Kelly Cromley
Sep 12, 2026
0

Sei Labs has acquired Bilinear Labs, a data analytics and indexing platform, in a deal announced in September 2026 as...

alpha ladder finance

Alpha Ladder Expands Access to Tokenized Global Equities

by Kelly Cromley
Sep 12, 2026
0

Singapore-based wealth manager Alpha Ladder Finance has launched access to Payward’s xStocks tokenized equities for institutional and accredited investors in...

Visa

MVB, Velocity Join Visa Stablecoin Settlement Pilot

by Kelly Cromley
Sep 12, 2026
0

MVB Financial Corp., a banking partner for fintech and technology companies, is participating with stablecoin payments platform Velocity in a...

tether stablecoin usdt

Tether Unveils Offline AI Translators for Africa and Europe

by Kelly Cromley
Sep 12, 2026
0

Tether, the issuer of the USDT stablecoin, has introduced a new set of open-source artificial intelligence translation models designed to...

TRON

TRON Adds Ethena’s USDe and sUSDe to Expand Digital Dollar Access

by Kelly Cromley
Sep 12, 2026
0

TRON has expanded its stablecoin offering by adding USDe and sUSDe from Ethena, giving developers and users access to additional...

Next Post
russia

Russia Approves Bitcoin, Ethereum and USDT Trading, Excludes XRP

  • Collé Ai

    Collé: Pioneering AI Web3 Platform Receives Investment Boost from BlackRock

    by Kelly Cromley
    May 13, 2024
  • Router Protocol and OpenWorldSwap Partnership to Revolutionize DEX Market

    by Kelly Cromley
    Aug 6, 2024
  • SmarTrust Brings Blockchain-Powered Escrow to Freelancers

    by Kelly Cromley
    May 1, 2025
  • Hyper Foundation Launched to Boost Hyperliquid Blockchain Development

    by Kelly Cromley
    Oct 15, 2024
  • Blockchain Based Sports Platform SportsMint Unveiled

    by Kelly Cromley
    Apr 30, 2024

Recent News

India
Market News

India’s NSDL Launches Blockchain Platform for Tokenized Bonds

by Kelly Cromley
Sep 13, 2026
Sei Labs
Market News

Sei Labs Acquires Bilinear Labs to Boost Blockchain Infrastructure

by Kelly Cromley
Sep 12, 2026
alpha ladder finance
Market News

Alpha Ladder Expands Access to Tokenized Global Equities

by Kelly Cromley
Sep 12, 2026
Visa
Market News

MVB, Velocity Join Visa Stablecoin Settlement Pilot

by Kelly Cromley
Sep 12, 2026
tether stablecoin usdt
Market News

Tether Unveils Offline AI Translators for Africa and Europe

by Kelly Cromley
Sep 12, 2026

Categories

  • Altcoin News
  • Analysis News
  • Binance Coin News
  • Bitcoin News
  • Blog
  • Cardano News
  • Ethereum News
  • ICO News
  • Legislation News
  • Market Forecasts
  • Market News
  • News
  • Ripple News
  • Solana News
  • Tether News
  • XRP
Trustpilot

Cointrust

  • About Us
  • Contact Us
  • Correction Request
  • Our Team

Legal

  • Disclaimer
  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy

Popular

  • ICO Listings
  • Knowledge Base
  • All about Mining
  • Cryptocurrency Exchanges
  • How and Where to buy Cryptocurrency

Sitemap

  • News section
  • Sitemap
  • XML Sitemap

© 2024 CoinTrust.com.

CoinTrustCoinTrust

* DISCLAIMER: All information provided in CoinTrust is merely for informational purposes, we are not an investment advisor and not affiliated with any companies or ICO/Cryptocurrency Projects. To use this website you must accept our cookie policy, Disclaimer and Privacy Policies.

No Result
View All Result
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos

© 2024 CoinTrust.com.

We use cookies to ensure that we give you the best experience on our website.
If you continue to use this site you agree to allow us to use cookies, in accordance with our Cookie Policy.