ClickFix WebRTC data-channel stager activity
Malware Activity
Summary
Hide ▲
Show ▼
The ClickFix payload now uses a WebRTC data-channel stager that opens a covert encrypted channel and executes received code in the browser, increasing stealth for visitors of compromised sites. The new variant replaces the earlier smart-contract payload and pulls JavaScript from a hardcoded C2 address. It buffers the code in memory and runs it when the channel closes or after ten seconds, avoiding disk writes. The change sits inside a broader delivery chain spread across thousands of hacked websites.
Related Happenings
BNB Smart Chain EtherHiding ClickFix campaign
Campaign
H score61
First: 05.09.2026 17:29
Last: 05.09.2026 17:29
Sources 1
How related:
A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC).
About this happening:
A massive cybercriminal operation is using more than 5,400 hacked websites to spread ClickFix payloads through EtherHiding on BNB Smart Chain (BSC), giving the...
BNB Smart Chain EtherHiding ClickFix campaign
CampaignHow related: A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC).
About this happening: A massive cybercriminal operation is using more than 5,400 hacked websites to spread ClickFix payloads through EtherHiding on BNB Smart Chain (BSC), giving the...
Timeline
-
05.09.2026 17:29 2 articles · 2h ago
ClickFix payload delivery shifts to a WebRTC data-channel stager
Technical Analysis UpdateNetskope researchers found a campaign that uses more than 5,400 hacked websites, mostly WordPress and PrestaShop sites, to deliver ClickFix payloads through EtherHiding on BNB Smart Chain (BSC) smart contracts. Later in the campaign, the threat actor replaced the ClickFix payload with a WebRTC data-channel stager that creates a peer connection and data channel, feeds back its own answer to bypass a normal handshake, and receives JavaScript from a hardcoded C2 address for in-memory execution on Windows visitors.
Show sources
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain — www.bleepingcomputer.com — 05.09.2026 17:29
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain — www.bleepingcomputer.com — 05.09.2026 17:29