Talos Takes
Talos Takes
Talos Takes·Sep 23, 2026·18m

ClickFix, EtherHiding, and the rise of malicious code in the blockchain

Show notes

In this episode of Talos Takes, Amy sits down with researcher Vanja Svajcer to break down a sophisticated, multi-stage infection chain that leverages a combination of ClickFix social engineering, WebDAV, and decentralized infrastructure.

Vanja walks us through how threat actors are repurposing legitimate user behaviors — like solving CAPTCHAs — to gain unauthorized access, and how they utilize blockchain smart contracts as bulletproof storage for malicious code. We also explore the divergence in final payloads, ranging from remote access tools to crypto-stealing malware. Tune in for actionable behavioral patterns that your security teams can monitor to detect these incidents before they progress.

Vanja's blog: https://blog.talosintelligence.com/clearfake-webdav-infection-chain/