BNB Smart Chain EtherHiding ClickFix campaign
Campaign
Summary
Hide ▲
Show ▼
A massive cybercriminal operation is using more than 5,400 hacked websites to spread ClickFix payloads through EtherHiding on BNB Smart Chain (BSC), giving the delivery chain durable infrastructure. The compromised sites are mostly WordPress and PrestaShop installations, and the operation has expanded to more than 300 infected websites every day. The scale and persistence point to a continuing delivery campaign rather than a one-off compromise.
Related Happenings
ClickFix WebRTC data-channel stager activity
Malware Activity
H score47
First: 05.09.2026 17:29
Last: 05.09.2026 17:29
Sources 1
How related:
The researchers note that later in the campaign, the threat actor replaced the ClickFix payload in the smart contract with a WebRTC data-channel stager.
About this happening:
The ClickFix payload now uses a WebRTC data-channel stager that opens a covert encrypted channel and executes received code in the browser, increasing stealth for visitors...
ClickFix WebRTC data-channel stager activity
Malware ActivityHow related: The researchers note that later in the campaign, the threat actor replaced the ClickFix payload in the smart contract with a WebRTC data-channel stager.
About this happening: The ClickFix payload now uses a WebRTC data-channel stager that opens a covert encrypted channel and executes received code in the browser, increasing stealth for visitors...
ErrTraffic ClickFix campaign delivering Cruciferra through compromised WordPress sites
Campaign
H score32
First: 19.08.2026 18:00
Last: 19.08.2026 18:00
Sources 1
About this happening:
An active ErrTraffic-generated ClickFix campaign is using compromised WordPress sites and clipboard-paste PowerShell lures to deliver Cruciferra, widening the malware...
ErrTraffic ClickFix campaign delivering Cruciferra through compromised WordPress sites
CampaignAbout this happening: An active ErrTraffic-generated ClickFix campaign is using compromised WordPress sites and clipboard-paste PowerShell lures to deliver Cruciferra, widening the malware...
ErrTraffic and Cruciferra subscription MaaS ecosystem outsources delivery and EDR evasion
Threat Actor Meta
H score32
First: 19.08.2026 18:00
Last: 19.08.2026 18:00
Sources 1
About this happening:
ErrTraffic and Cruciferra are being sold as subscription MaaS services, expanding the underground market for ClickFix delivery and EDR-killing capabilities. Th...
ErrTraffic and Cruciferra subscription MaaS ecosystem outsources delivery and EDR evasion
Threat Actor MetaAbout this happening: ErrTraffic and Cruciferra are being sold as subscription MaaS services, expanding the underground market for ClickFix delivery and EDR-killing capabilities. Th...
StopAndProtect hacked-WordPress cybercrime campaign
Campaign
H score49
First: 19.08.2026 14:25
Last: 19.08.2026 14:25
Sources 1
About this happening:
The StopAndProtect campaign now abuses nearly 2,000 hacked WordPress sites to deliver malware, steal files, and manage infected hosts, expanding a distributed criminal inf...
StopAndProtect hacked-WordPress cybercrime campaign
CampaignAbout this happening: The StopAndProtect campaign now abuses nearly 2,000 hacked WordPress sites to deliver malware, steal files, and manage infected hosts, expanding a distributed criminal inf...
Operation Endgame international cybercrime disruption initiative
Public Sector Action
H score57
First: 19.06.2026 18:07
Last: 19.06.2026 18:07
Sources 1
About this happening:
Operation Endgame is an ongoing international law enforcement initiative that now includes the takedown of SocGholish infrastructure, expanding disruption of botnets a...
Operation Endgame international cybercrime disruption initiative
Public Sector ActionAbout this happening: Operation Endgame is an ongoing international law enforcement initiative that now includes the takedown of SocGholish infrastructure, expanding disruption of botnets a...
Timeline
-
05.09.2026 17:29 2 articles · 2h ago
Compromised websites deliver ClickFix payloads through BNB Smart Chain smart contracts
Campaign Scope UpdateA massive cybercriminal operation is leveraging more than 5,400 hacked websites, mostly WordPress and PrestaShop sites, to deliver ClickFix payloads through EtherHiding on BNB Smart Chain (BSC). The compromised sites inject a script that retrieves the next-stage payload from a smart contract on the BSC Testnet endpoint, shows a fake CAPTCHA, and instructs visitors to open the Windows Run dialog and paste a PowerShell command. Later in the campaign, the threat actor replaced the ClickFix payload with a WebRTC data-channel stager that receives JavaScript code from a hardcoded command-and-control (C2) address and executes it in the browser, while telemetry showed more than 300 infected websites every day, nearly 400 daily endpoint calls in August, and an all-time peak of 536.
Show sources
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain — www.bleepingcomputer.com — 05.09.2026 17:29
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain — www.bleepingcomputer.com — 05.09.2026 17:29