research
Published 2026-09-17
Verified 2026-09-21

GuidePoint: EtherHiding on Polygon — ClickFix sites → fake browser extension for bank/crypto 2FA

GuidePoint Security (blog 17 September 2026; Cyber Security News wire 21 September) documents a multi-month EtherHiding campaign on Polygon: at least 31 compromised legitimate websites and 15 smart contracts underpin C2 rotation so operators change backends with a low-cost chain transaction without updating earlier stages. Victims hit via Google/Bing land on injected fake-CAPTCHA ClickFix overlays (Windows+R → paste → Enter); a scheduled task named Enter retrieves next-stage scripts, Registry reboot persistence is set, and a script queries Polygon for the active control server. The backdoor later installs a fake browser extension that intercepts credentials and two-factor codes from roughly 479 financial and cryptocurrency sites. Distinct from desk card clickfix-etherhiding-bsc-20260905 (Netskope / BSC Testnet payload fetch) and from chainscript-clickfix-polygon-20260918 (Blackpoint Node.js RAT with Polygon WebSocket C2) — overlapping EtherHiding idea, different delivery/goals. Primary: GuidePoint; secondary: CSN.

Product
EtherHiding ClickFix → Polygon smart-contract C2 + fake browser extension (bank/crypto credential & 2FA theft)
Versions
n/a (malware / compromised websites; ~31 sites / 15 Polygon contracts / ~479 finance-crypto targets per GuidePoint)
Exploited in Australia?
unknown
Patch to
Treat unexpected Windows+R / paste CAPTCHA prompts as hostile; hunt scheduled task Enter and unexpected browser extensions; block/monitor Polygon RPC and related EtherHiding C2 patterns where policy allows; review compromised marketing/site JS injections.

Primary: GuidePoint Security — EtherHiding Exposed (17 Sep 2026) · Vendor: GuidePoint Security primary analysis · Cyber Security News — blockchain C2 / bank-login EtherHiding wire (21 Sep 2026)

tech identity network