← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 11, 2026 · 07:47via CyberPress

ErrTraffic MaaS Hides Malware Infrastructure in Polygon Blockchain Smart Contracts

Brief

The attack combines ClickFix social engineering, blockchain-based EtherHiding, and dynamic infrastructure delivery to make detection and takedown harder.

According to research by WatchGuard Threat Lab member Euler Neto, ErrTraffic operators use Polygon blockchain smart contracts to store or resolve malicious infrastructure rather than placing command-and-control (C2) addresses directly inside injected website code.

This approach allows attackers to update their delivery infrastructure without changing the compromised sites hosting the initial lure.

The campaign has delivered threats including Vidar, Okobot, LegionLoader, OnionDrop-related payloads, and BabaDedaLoader.

WatchGuard telemetry also identified additional payload variants, DLL side-loading activity, browser-targeting behavior, and techniques designed to weaken endpoint defenses.

Read more on CyberPress