MalwareBleeping Computer
8.0 — CRITICAL
Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain
A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
A large-scale cyber operation is using over 5,400 compromised small-business websites to deliver ClickFix payloads stored on the BNB Smart Chain (BSC), leveraging the EtherHiding technique for resilient delivery.
⚙️Technical Details
Affected Systems
WordPressPrestaShop
Attack Vectors
EtherHidingClickFix lureWebRTC data-channel stager
💥Impact Assessment
Severity: high
Who Is at Risk
Small-business websites built on WordPress and PrestaShop, potentially with valid credentials
🛡️Recommended Actions
1Block the entire pool of BSC testnet RPC endpoints
2Monitor for non-web UDP traffic associated with WebRTC
3Implement prevention measures to hide what happens after initial access
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
