At least 31 organizations have fallen victim to a sophisticated cyberattack campaign known as ClickFix, which leverages the Polygon blockchain through a technique called EtherHiding. This campaign has targeted websites across various sectors including e-commerce, professional services, and retail logistics. The attackers utilize the decentralized nature of the Polygon blockchain to dynamically update their command-and-control (C2) server addresses, making it challenging to block their operations. According to GuidePoint Security's Research and Intelligence Team, this approach allows attackers to avoid detection by changing C2 details seamlessly and at a minimal cost. Unlike typical ClickFix campaigns, which deploy an infostealer that can be neutralized by blocking a single C2 server, this attack employs a more complex method. The malware involved uses a dropper that connects to a staging server, installing both the C2 agent and a persistence mechanism on the victim's systems. The campaign further distinguishes itself by utilizing a Search Engine Poisoning system and malicious JavaScript to exploit CloudFlare's human verification process. The attackers compromise business websites, embedding harmful code that leads unsuspecting users to execute malware. This method has been likened to other campaigns using EtherHiding, where compromised e-commerce platforms are the initial targets. The malware embedded in victims' systems contacts the Polygon blockchain for updated instructions, making detection and mitigation difficult. Researchers note that the success of such campaigns often hinges on human error, emphasizing the need for improved phishing training and security measures within organizations.