Three dollars buys four months of takedown-proof C2 infrastructure

A Fourth Door: Compromised Legitimate Sites in the Polygon EtherHiding macOS Campaign

1. What this adds Between June and August 2026, several teams published detailed analyses of a macOS campaign that pairs ClickFix social engineering with EtherHiding, a technique that stores the command-and-control address inside a public blockchain smart contract rather than hardcoding a domain. The malware chain is, at this point, well documented. Have I Been Squatted published the most complete technical breakdown on 6 July 2026, covering the loader, the LaunchAgent persistence, the module taxonomy and the Polygon contract itself. UnderDefense documented a separate delivery path through malicious Chrome extensions on 29 July. Prophet Security described a third, with initial access consistent with fake-interview tradecraft. Earlier still, p0pcycle flagged the on-chain C2 pattern in June, and fab0 has been publishing each new C2 domain on X as the operator rotates it. ...

September 7, 2026 · 22 min · Mehmet Buğra Şahinoğlu