ErrTraffic MaaS Hides Malware Infrastructure in Polygon Blockchain Smart Contracts
Brief
The attack combines ClickFix social engineering, blockchain-based EtherHiding, and dynamic infrastructure delivery to make detection and takedown harder.
According to research by WatchGuard Threat Lab member Euler Neto, ErrTraffic operators use Polygon blockchain smart contracts to store or resolve malicious infrastructure rather than placing command-and-control (C2) addresses directly inside injected website code.
This approach allows attackers to update their delivery infrastructure without changing the compromised sites hosting the initial lure.
The campaign has delivered threats including Vidar, Okobot, LegionLoader, OnionDrop-related payloads, and BabaDedaLoader.
WatchGuard telemetry also identified additional payload variants, DLL side-loading activity, browser-targeting behavior, and techniques designed to weaken endpoint defenses.
