Advertise
CoinTrust
BTC
ETH
BCH
SOL
DOGE
SHIB
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
No Result
View All Result

Home » Hackers Hide Malware Infrastructure on Polygon Blockchain

Hackers Hide Malware Infrastructure on Polygon Blockchain

ClickFix Campaign Uses Compromised WordPress Sites

Kelly Cromley by Kelly Cromley
Aug 12, 2026
in Market News, News
Reading Time: 3 mins read
0
Malware

Cybersecurity researchers have uncovered a malware campaign that uses the Polygon blockchain to conceal parts of its infrastructure, allowing attackers to make their delivery network more difficult to disrupt.

The campaign, tracked as ErrTraffic, compromises WordPress websites and turns them into launch points for fake verification pages. Visitors are presented with prompts resembling browser checks or CAPTCHA procedures and are persuaded to execute Windows commands themselves. The technique, known as ClickFix, relies on social engineering rather than exploiting a software vulnerability.

Once a victim follows the instructions and runs the command, malware can be downloaded onto the system. Depending on the payload, attackers may gain access to browser information, stored credentials, cookies, and cryptocurrency wallet data.

WatchGuard analysts identified the activity through their telemetry and connected it to an ErrTraffic malware-as-a-service operation promoted by a forum user operating under the name LenAI. The infrastructure was found to distribute several malware families, including Vidar, Okobot, LegionLoader, OnionDrop-related payloads and BabaDedaLoader.

The campaign combines a convincing user interaction with blockchain-backed infrastructure, allowing attackers to change delivery details without modifying every compromised website.

Polygon Smart Contracts Help Conceal Infrastructure

The campaign begins when a visitor accesses an infected WordPress website. Malicious JavaScript injected into the page does not openly reveal the attacker’s final destination. Instead, it communicates with Polygon through remote procedure call services and retrieves configuration information stored in a smart contract.

That information is then used to identify the current attacker-controlled infrastructure. The technique, commonly referred to as EtherHiding, can complicate takedown efforts because attackers can modify information stored in the blockchain without having to update the malicious code placed on every infected website.

The infrastructure also incorporates traffic routing and location-based filtering, giving operators greater flexibility in deciding which visitors receive the malicious content. The resulting setup can allow different affiliates or operators to change delivery paths while maintaining the same basic social-engineering strategy.

The final PowerShell command may download a randomly named 7-Zip executable together with a similarly randomized payload or retrieve the malicious payload directly. This approach makes the victim responsible for the execution step while the attacker avoids relying solely on traditional software vulnerabilities.

Multiple Malware Families Increase the Risk

The range of malware delivered through the campaign adds to the threat. Vidar, for example, can target browser and cryptocurrency wallet information. Researchers observed versions communicating through services including Telegram, Steam and a compromised Brazilian website.

Another Vidar variant was observed creating remote threads inside Chrome and Edge processes, potentially allowing attackers to access information maintained by those browsers.

Okobot was also identified in the campaign. It arrived through a ZIP archive containing a file named Volume2 and a malicious DLL. Researchers found that the malware attempted to weaken Microsoft Defender protections and interfere with security mechanisms surrounding LSASS, a Windows process that manages sensitive authentication information.

Other components included a malicious MSI package containing a Node.js backdoor that used Tor for command-and-control communications. Researchers also identified OnionDrop variants that used DLL side-loading to conceal malicious activity behind legitimate applications.

Additional infection chains were associated with LegionLoader and BabaDedaLoader, demonstrating that the infrastructure could support multiple malware families rather than a single threat.

Defenders Urged to Monitor the Entire Attack Chain

Security teams should focus on preventing fake verification prompts from becoming execution points and should investigate suspicious PowerShell activity, browser process injection, and unusual downloads following visits to compromised websites.

Organizations can also look for WordPress sites that create the errtraffic_session cookie and examine network connections to Polygon RPC services that occur immediately after visits to suspicious pages. Newly created DLL files and unexpected downloads can provide additional indicators of compromise.

Keeping WordPress installations, plugins, and themes updated, while removing injected scripts, can reduce the number of websites available to attackers.

The campaign highlights a broader shift in cybercrime tactics in which legitimate technologies are repurposed to conceal malicious operations. Blockchain infrastructure, Windows utilities, browser processes, and trusted websites can each serve a limited function within an attack, but their combination can make the overall operation harder to identify and disrupt.

Monitoring the complete infection chain instead of focusing on a single malware family could give organizations a better chance of detecting future variations of the ErrTraffic campaign.

Previous Post

Broadridge Blockchain Repo Platform Hits $8 Trillion in July

Next Post

Russia Approves Bitcoin, Ethereum and USDT Trading, Excludes XRP

Related Posts

Itaú Unibanco

Itaú Tests Tokenized Bonds and Funds on Blockchain

by Kelly Cromley
Aug 12, 2026
0

Itaú Unibanco, Brazil’s largest bank, is expanding its digital asset strategy by testing the issuance of tokenized bonds and investment...

Bermuda

Bermuda Adopts Stellar Blockchain for Financial Infrastructure

by Kelly Cromley
Aug 12, 2026
0

Bermuda is advancing its use of blockchain technology by integrating the Stellar network into its financial infrastructure, a move that...

solana name service

Solana Name Service and Solflare Advance .sol Upgrade

by Kelly Cromley
Aug 12, 2026
0

Solana Name Service and Solflare are collaborating to support an upgrade to .sol domains for users holding Solana-based names. The...

russia

Russia Approves Bitcoin, Ethereum and USDT Trading, Excludes XRP

by Kelly Cromley
Aug 12, 2026
0

Russia has approved trading in Bitcoin, Ethereum and Tether’s USDT, creating new opportunities for institutional participation in selected digital assets...

Broadridge Financial Solutions

Broadridge Blockchain Repo Platform Hits $8 Trillion in July

by Kelly Cromley
Aug 11, 2026
0

Broadridge Financial Solutions’ blockchain-based repo platform processed about $8 trillion in transactions during July, highlighting the growing use of distributed...

ravencoin

Ravencoin Faces Four-Day Blockchain Rollback After Attack

by Kelly Cromley
Aug 11, 2026
0

Ravencoin is facing a potential rollback of roughly four days of blockchain activity after attackers exploited a critical software vulnerability...

Next Post
russia

Russia Approves Bitcoin, Ethereum and USDT Trading, Excludes XRP

  • Collé Ai

    Collé: Pioneering AI Web3 Platform Receives Investment Boost from BlackRock

    by Kelly Cromley
    May 13, 2024
  • Router Protocol and OpenWorldSwap Partnership to Revolutionize DEX Market

    by Kelly Cromley
    Aug 6, 2024
  • SmarTrust Brings Blockchain-Powered Escrow to Freelancers

    by Kelly Cromley
    May 1, 2025
  • Hyper Foundation Launched to Boost Hyperliquid Blockchain Development

    by Kelly Cromley
    Oct 15, 2024
  • Blockchain Based Sports Platform SportsMint Unveiled

    by Kelly Cromley
    Apr 30, 2024

Recent News

Itaú Unibanco
Market News

Itaú Tests Tokenized Bonds and Funds on Blockchain

by Kelly Cromley
Aug 12, 2026
Bermuda
Market News

Bermuda Adopts Stellar Blockchain for Financial Infrastructure

by Kelly Cromley
Aug 12, 2026
solana name service
Market News

Solana Name Service and Solflare Advance .sol Upgrade

by Kelly Cromley
Aug 12, 2026
russia
Bitcoin News

Russia Approves Bitcoin, Ethereum and USDT Trading, Excludes XRP

by Kelly Cromley
Aug 12, 2026
Malware
Market News

Hackers Hide Malware Infrastructure on Polygon Blockchain

by Kelly Cromley
Aug 12, 2026

Categories

  • Altcoin News
  • Analysis News
  • Binance Coin News
  • Bitcoin News
  • Blog
  • Cardano News
  • Ethereum News
  • ICO News
  • Legislation News
  • Market Forecasts
  • Market News
  • News
  • Ripple News
  • Solana News
  • Tether News
  • XRP
Trustpilot

Cointrust

  • About Us
  • Contact Us
  • Correction Request
  • Our Team

Legal

  • Disclaimer
  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy

Popular

  • ICO Listings
  • Knowledge Base
  • All about Mining
  • Cryptocurrency Exchanges
  • How and Where to buy Cryptocurrency

Sitemap

  • News section
  • Sitemap
  • XML Sitemap

© 2024 CoinTrust.com.

CoinTrustCoinTrust

* DISCLAIMER: All information provided in CoinTrust is merely for informational purposes, we are not an investment advisor and not affiliated with any companies or ICO/Cryptocurrency Projects. To use this website you must accept our cookie policy, Disclaimer and Privacy Policies.

No Result
View All Result
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos

© 2024 CoinTrust.com.

We use cookies to ensure that we give you the best experience on our website.
If you continue to use this site you agree to allow us to use cookies, in accordance with our Cookie Policy.