ClickFix via EtherHiding: 5,400+ sites pull payloads from BSC Testnet smart contracts
Netskope Threat Labs (covered by BleepingComputer, 5 September 2026) describe an ongoing campaign on more than 5,400 compromised sites (mostly WordPress and PrestaShop) that inject a script fetching the next-stage payload from a Binance Smart Chain Testnet smart contract — EtherHiding — so operators can rotate payloads without retaking the site. The lure is ClickFix: a fake CAPTCHA that tells the visitor to open Windows Run and paste a PowerShell command. Later variants replace the ClickFix stage with a WebRTC data-channel stager that opens a covert channel to attacker infrastructure and runs received JavaScript in browser memory. Telemetry showed roughly 300–400 sites hitting BSC Testnet RPC endpoints daily through summer 2026, peaking near 536 in August. Distinct from the ACSC ClickFix/Vidar-via-WordPress Australia advisory (separate desk card): this card is the blockchain-backed delivery pattern. Defenders: block BSC Testnet RPC where policy allows, treat unexpected Run/paste prompts as hostile, and hunt injected site scripts that call testnet endpoints. Primary: Netskope blog.
- Exploited in Australia?
- unknown
Primary: Netskope — malware on the blockchain / WebRTC twist · BleepingComputer (5 Sep 2026)
