Sending Logs, Alerts, and Telemetry Through a Data Diode

Find Out How
We utilize artificial intelligence for site translations, and while we strive for accuracy, they may not always be 100% precise. Your understanding is appreciated.

Inside a Live ClickFix Campaign using EtherHiding to Hide Its Next Move

Our live investigation followed one attack chain from a user's copy-paste to a smart contract that's still active and still pointing somewhere.
By Vivien Vereczki
Share this Post

ClickFix and EtherHiding combine user-driven command execution with blockchain-based configuration. ClickFix persuades a user to run a command, while EtherHiding allows attackers to direct later stages through public smart contracts. Together, they create a delivery path that challenges indicator-based detection and conventional disruption methods.

Key Takeaways

  • ClickFix turns familiar verification and troubleshooting workflows into paths for user-executed commands
  • EtherHiding separates disposable delivery infrastructure from a more persistent configuration layer
  • Blocking a known domain doesn’t reveal or disable the mechanism directing the next stage
  • SOC teams need to connect evidence held across multiple tools and teams
  • Compromised websites can make malicious instructions appear to come from a trusted digital property
  • The FileScan.io Threat Labs investigation shows how researchers traced these relationships in a live chain

What Makes ClickFix Different from Conventional Phishing?

ClickFix is a social engineering technique that instructs users to copy, paste, or execute a command under the pretext of completing a CAPTCHA, fixing a browser problem, opening a document, or resolving an access issue.

MITRE ATT&CK classifies ClickFix as Malicious Copy and Paste, T1204.004. The technique relies on users placing attacker-provided code directly into a command or scripting interface rather than opening a conventional malicious attachment.

The interaction can resemble normal troubleshooting. Verification prompts, browser errors, and access checks are common online, giving attackers a familiar workflow to imitate. For defenders, the earliest useful signal is often behavioral. A browser session followed by unusual command execution can matter more than the presence of a familiar malicious file.

How EtherHiding Changes the Infrastructure Problem

EtherHiding uses blockchain smart contracts to store or return attacker-controlled configuration. This separates the infrastructure visible to the victim from the mechanism that tells the campaign where to go next. Defenders can take down a domain or hosting account, but the wider chain stays viable as long as its configuration layer can direct traffic toward replacement infrastructure.

Our FileScan.io Threat Labs investigation traced a live ClickFix chain through an injected script, a Polygon smart contract, and the infrastructure it resolved during the research. The investigation report describes the artifacts, pivots, validation process, and relationships that established that connection.

Defenders are dealing with more than a collection of short-lived malicious domains. They need to identify the persistent relationships behind infrastructure designed to appear disposable.

Why Should Security and Engineering Teams Care?

ClickFix and EtherHiding create a visibility problem that can cross organizational boundaries. The web team spots an unauthorized script, endpoint security flags an unusual command, network tools log outbound traffic, and threat intelligence recognizes only one piece of the infrastructure. Each signal appears incomplete on its own.

SOC professionals

SOC analysts and threat hunters need enough context to distinguish an isolated suspicious event from one stage in a broader chain. The challenge is not simply finding another indicator, but connecting activity that appears across browsers, endpoints, networks, identities, and public infrastructure.

SOC leaders also face a coordination issue. Separate teams may hold different parts of the evidence, making shared timelines and clear ownership important during investigation.

Software engineers and web teams

Software and web teams matter because legitimate digital properties can become delivery surfaces. Compromised websites, injected scripts, and abused administrative access can place malicious instructions inside an environment that users already trust.

Web telemetry can therefore become security evidence. Version history, deployment records, content-integrity alerts, and administrative logs help establish when suspicious content appears and how it relates to endpoint activity.

Which Organizations Face Greater Consequences?

ClickFix is not confined to a single sector because it exploits user behavior rather than an industry-specific technology. The consequences are greater for organizations that hold valuable credentials, operate customer-facing digital services, manage sensitive information, or have little tolerance for disruption.

This includes critical infrastructure operators, government agencies, regulated organizations, software providers, managed service providers, and enterprises with large or distributed workforces. In these sectors, a compromised identity, endpoint, or trusted website can disrupt operations, not just data.

Types of Damages a ClickFix Campaign Can Cause

ClickFix is a delivery technique, so the eventual impact depends on the payload and the access available on the affected device. In a recent blog article, we have documented ClickFix payloads ranging from infostealers to full-network ransomware, and how the technique's rapid nation-state adoption has made it difficult for SOC teams to triage.

Our specific FileScan.io investigation focused on the delivery mechanism. It did not claim attribution of the final payload. The research therefore does not establish that the traced chain caused ransomware, fraud, credential theft, or another particular outcome. That boundary is important. The research shows how a delivery chain can be reconstructed even when its visible infrastructure changes.

Three Visibility Gaps Familiar Defenses Miss

ClickFix and EtherHiding divide the attack across human behavior, legitimate system tools, web content, public infrastructure, and changing destinations.

Three visibility gaps stand out:

  • User activity can resemble legitimate troubleshooting. The user may voluntarily open a command interface and execute the supplied instruction.
  • Visible infrastructure can be replaced. A blocked domain may represent only one temporary component of the chain.
  • Security tools hold disconnected evidence. Browser, process, network, identity, and website events can land in separate systems.

What Does the FileScan.io Investigation Add?

Our FileScan.io Threat Labs research goes beyond the general description of ClickFix and EtherHiding. It documents how researchers moved from a live lure to the infrastructure and blockchain activity connected to it.

The full analysis covers:

  • A live blockchain call, made and captured in real time, tracing the chain to the destination it resolved to at the time of the research
  • More than a dozen related smart contracts tied to two separate wallets and what that pattern suggests about how the operator runs this
  • One lure impersonating a well-known AI brand that hadn't been publicly documented before this research
  • Two independent researchers who reached the same wallet and contract through entirely separate paths

Read the complete technical trace and the evidence that connected its moving parts.

Frequently Asked Questions

What is ClickFix?

ClickFix is a social engineering technique that persuades users to copy, paste, or run a malicious command as part of a supposed fix, verification step, or access requirement. The user initiates execution, which can make the opening event look different from a conventional malicious attachment.

What is EtherHiding?

EtherHiding is a technique that uses blockchain smart contracts to store or return attacker-controlled configuration. This can give a campaign a persistent reference point while its visible domains and servers change.

Why can rotating infrastructure complicate detection?

Rotating infrastructure can make individual indicators expire quickly. Defenders may block one destination without identifying the relationship or configuration mechanism that directs the campaign toward its replacement.

Did the FileScan.io investigation identify the final malware?

No. The investigation focused on tracing and validating the delivery mechanism. The researchers did not claim final-payload attribution.

How many related contracts did researchers find, and what do they reveal about the operator?

More than a dozen; enough to show how far this operator's infrastructure extends beyond the single contract we traced. The full breakdown, including wallet-level attribution, is in the FileScan.io Threat Labs article.

Stay Up-to-Date With OPSWAT!

Sign up today to receive the latest company updates, stories, event info, and more.