Executive Summary
In July 2026, researchers identified a sophisticated ClickFix campaign targeting Artlist's blog subdomain. The attack originated from an infostealer infection three years prior, where a developer's machine was compromised via pirated software. The stolen credentials allowed threat actors to bypass perimeter security and inject malicious JavaScript into the trusted corporate domain.
The campaign utilizes 'EtherHiding,' a technique where obfuscated JavaScript queries a smart contract on the Polygon blockchain to retrieve dynamic C2 URLs. This provides the infrastructure with high resilience against domain takedowns. Victims are lured via a fake reCAPTCHA that social-engineers them into executing a PowerShell command via keyboard shortcuts (Win+X, I, Ctrl+V, Enter), leading to a multi-stage malware infection.
The final payload is a highly capable Remote Access Trojan (RAT) featuring keylogging, live screen streaming, and a hidden desktop subsystem. Notably, it includes a Tor fallback mechanism to maintain C2 communications if primary servers are blocked, highlighting the advanced persistence capabilities of this threat actor group.
