Find notable cyber news and cases, enriched with sources, timelines, and signals.

ClickFix WebRTC data-channel stager activity

Malware Activity
First reported
Last updated
Happening score
H score 47
1 unique sources, 1 articles

Summary

Hide ▲

The ClickFix payload now uses a WebRTC data-channel stager that opens a covert encrypted channel and executes received code in the browser, increasing stealth for visitors of compromised sites. The new variant replaces the earlier smart-contract payload and pulls JavaScript from a hardcoded C2 address. It buffers the code in memory and runs it when the channel closes or after ten seconds, avoiding disk writes. The change sits inside a broader delivery chain spread across thousands of hacked websites.

Related Happenings

BNB Smart Chain EtherHiding ClickFix campaign

Campaign
H score61 First: 05.09.2026 17:29 Last: 05.09.2026 17:29 Sources 1

How related: A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC).

About this happening: A massive cybercriminal operation is using more than 5,400 hacked websites to spread ClickFix payloads through EtherHiding on BNB Smart Chain (BSC), giving the...

Timeline

  1. 05.09.2026 17:29 2 articles · 2h ago

    ClickFix payload delivery shifts to a WebRTC data-channel stager

    Technical Analysis Update

    Netskope researchers found a campaign that uses more than 5,400 hacked websites, mostly WordPress and PrestaShop sites, to deliver ClickFix payloads through EtherHiding on BNB Smart Chain (BSC) smart contracts. Later in the campaign, the threat actor replaced the ClickFix payload with a WebRTC data-channel stager that creates a peer connection and data channel, feeds back its own answer to bypass a normal handshake, and receives JavaScript from a hardcoded C2 address for in-memory execution on Windows visitors.

    Show sources