Interestana
Home/News/5,400+ Hacked Sites Serve Blockchain-Stored ClickFix Payloads
BleepingComputer3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

5,400+ Hacked Sites Serve Blockchain-Stored ClickFix Payloads

A large-scale cybercriminal campaign has been identified, utilizing over 5,400 compromised small-business websites to distribute ClickFix malware. The malicious payloads are notably stored within smart contracts on the BNB Smart Chain (BSC), a blockchain platform. This sophisticated operation allows attackers to maintain control over the malware distribution even if individual websites are cleaned or taken offline. The ClickFix malware is designed to redirect users to fraudulent websites, often impersonating legitimate services to steal credentials or financial information. Researchers from Sucuri, a web security company, first observed this activity in late May 2024, with the campaign escalating significantly in early June. The compromised websites are primarily small to medium-sized businesses, which often have less robust security measures in place, making them easier targets for initial infection. The attackers exploit vulnerabilities in website content management systems (CMS) or plugins to gain unauthorized access. Once a site is compromised, the attackers embed malicious JavaScript code that redirects visitors to a landing page. This landing page then serves the ClickFix payload, which is retrieved from a smart contract on the BNB Smart Chain. The use of blockchain technology for storing malware payloads represents an evolving tactic by cybercriminals, aiming to enhance the resilience and persistence of their operations. Blockchain's decentralized and immutable nature makes it difficult for security researchers and law enforcement to disrupt the distribution chain. The BNB Smart Chain, developed by Binance, is a popular platform for decentralized applications and smart contracts, making it an attractive, albeit illicit, infrastructure for these actors. The scale of the operation, affecting over 5,400 distinct websites, highlights the widespread nature of the threat and the potential impact on unsuspecting internet users. Sucuri's analysis indicates that the campaign is ongoing and actively evolving, with new websites being compromised and added to the network regularly. The primary goal of the ClickFix malware, as observed in previous campaigns, is to generate fraudulent advertising revenue or to facilitate phishing attacks. Users who visit these compromised sites are at risk of being redirected to fake login pages for services like Google, Microsoft, or banking institutions, or to pages displaying deceptive advertisements. The security implications are significant, as it underscores the need for continuous vigilance in website security, particularly for smaller businesses that may lack dedicated IT security teams. Regular security audits, prompt patching of vulnerabilities, and the use of reputable security plugins are crucial steps to mitigate the risk of such compromises. The integration of blockchain into malware distribution methods poses a new challenge for cybersecurity professionals, requiring innovative approaches to detection and mitigation. The campaign's reliance on a decentralized ledger for payload storage suggests a trend towards more resilient and harder-to-trace cybercriminal infrastructure.

Original source — read the full reporting at the publisher:

Read on BleepingComputer

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next