Find notable cyber news and cases, enriched with sources, timelines, and signals.

BNB Smart Chain EtherHiding ClickFix campaign

Campaign
First reported
Last updated
Happening score
H score 61
1 unique sources, 1 articles

Summary

Hide ▲

A massive cybercriminal operation is using more than 5,400 hacked websites to spread ClickFix payloads through EtherHiding on BNB Smart Chain (BSC), giving the delivery chain durable infrastructure. The compromised sites are mostly WordPress and PrestaShop installations, and the operation has expanded to more than 300 infected websites every day. The scale and persistence point to a continuing delivery campaign rather than a one-off compromise.

Related Happenings

ClickFix WebRTC data-channel stager activity

Malware Activity
H score47 First: 05.09.2026 17:29 Last: 05.09.2026 17:29 Sources 1

How related: The researchers note that later in the campaign, the threat actor replaced the ClickFix payload in the smart contract with a WebRTC data-channel stager.

About this happening: The ClickFix payload now uses a WebRTC data-channel stager that opens a covert encrypted channel and executes received code in the browser, increasing stealth for visitors...

ErrTraffic ClickFix campaign delivering Cruciferra through compromised WordPress sites

Campaign
H score32 First: 19.08.2026 18:00 Last: 19.08.2026 18:00 Sources 1

About this happening: An active ErrTraffic-generated ClickFix campaign is using compromised WordPress sites and clipboard-paste PowerShell lures to deliver Cruciferra, widening the malware...

ErrTraffic and Cruciferra subscription MaaS ecosystem outsources delivery and EDR evasion

Threat Actor Meta
H score32 First: 19.08.2026 18:00 Last: 19.08.2026 18:00 Sources 1

About this happening: ErrTraffic and Cruciferra are being sold as subscription MaaS services, expanding the underground market for ClickFix delivery and EDR-killing capabilities. Th...

StopAndProtect hacked-WordPress cybercrime campaign

Campaign
H score49 First: 19.08.2026 14:25 Last: 19.08.2026 14:25 Sources 1

About this happening: The StopAndProtect campaign now abuses nearly 2,000 hacked WordPress sites to deliver malware, steal files, and manage infected hosts, expanding a distributed criminal inf...

Operation Endgame international cybercrime disruption initiative

Public Sector Action
H score57 First: 19.06.2026 18:07 Last: 19.06.2026 18:07 Sources 1

About this happening: Operation Endgame is an ongoing international law enforcement initiative that now includes the takedown of SocGholish infrastructure, expanding disruption of botnets a...

Timeline

  1. 05.09.2026 17:29 2 articles · 2h ago

    Compromised websites deliver ClickFix payloads through BNB Smart Chain smart contracts

    Campaign Scope Update

    A massive cybercriminal operation is leveraging more than 5,400 hacked websites, mostly WordPress and PrestaShop sites, to deliver ClickFix payloads through EtherHiding on BNB Smart Chain (BSC). The compromised sites inject a script that retrieves the next-stage payload from a smart contract on the BSC Testnet endpoint, shows a fake CAPTCHA, and instructs visitors to open the Windows Run dialog and paste a PowerShell command. Later in the campaign, the threat actor replaced the ClickFix payload with a WebRTC data-channel stager that receives JavaScript code from a hardcoded command-and-control (C2) address and executes it in the browser, while telemetry showed more than 300 infected websites every day, nearly 400 daily endpoint calls in August, and an all-time peak of 536.

    Show sources