# ClickFix campaign rotates malware lures through blockchain record

_Published Thursday, September 24, 2026 at 8:07 AM EDT · Security · Latest · Tier 2 — Notable_

![ClickFix campaign rotates malware lures through blockchain record — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiOah63YM6pjk2RAIcCXy-NSbO_uPPCSp4DsR-9-jeGLCRZCd9E1QSd0_b4c6xc5wFp_ncqCH3LPtBR_C1auF3Fid-DNSCtQh9eEArgNe0syhvA4I9EdDU454uAqieiAGyyI-dXW5AsA5X4zsbhTpHKjXfIbgM35i4MOC7Jcbk5SiILRU9_BgcV2H-_BxI/s1700-nu-rw-lo-l85-e365/ctm360.jpg)

Security firm CTM360 says its analysis of more than 17,000 infected URLs found a ClickFix campaign that can change its malicious destination without editing the compromised websites. ClickFix presents a fake website problem and persuades visitors to paste a command into a trusted system tool. In the campaign studied, visitors' browsers read a Polygon blockchain contract that supplies the current lure address.

CTM360 also examined a compromised WordPress site where the attack adjusted what visitors saw by operating system and withheld payloads based on machine identity. About 3,000 of the URLs were still serving the lure when the firm wrote its report. CTM360 assessed a link to a Vidar malware distribution cluster with moderate confidence because affiliates can share the underlying framework.

## Sources

- [The Hacker News](https://thehackernews.com/2026/09/17000-urls-reveal-how-clickfix-turns.html)

---
Canonical: https://techandbusiness.org/newswire/jrxFPzbpk2cA4tewLvTuVx
Published: 2026-09-24T12:07:50.106Z
Story chronology: 2026-09-24T09:14:21.000Z
Retrieved: 2026-09-24T15:08:26.620Z
Publisher: Tech & Business (techandbusiness.org)
