ClickFix is the social engineering technique that persuades a user to paste and run a command, while EtherHiding is a delivery method that stores kit configuration on a public blockchain instead of a removable web server. In practice, EtherHiding helps attackers keep lures and payloads alive, while ClickFix describes how the victim is manipulated into execution.
Why the two techniques matter in the same attack chain
ClickFix and EtherHiding solve different problems for attackers. ClickFix is the human-execution step, a lure that turns a browser session into a copied command and an unintended run. EtherHiding is the persistence and delivery step, where the attacker keeps configuration or payload references on blockchain infrastructure rather than on a takedown-prone web host.
The practical difference is that ClickFix depends on manipulating the victim at the moment of execution, while EtherHiding helps the campaign survive site cleanup, domain suspension, or routine web content removal. That makes them complementary rather than interchangeable.
Seen together, they often form a chain: the lure gets the command executed, and the hidden delivery layer keeps the kit reachable even when the visible landing page changes. That combination is attractive because it reduces the attacker’s dependence on a single disposable server.
How the attack flow differs from a normal browser-based lure
In a typical browser-based campaign, the visible page and the payload host are tightly coupled. Remove the page, block the domain, or take down the server, and the chain weakens. EtherHiding breaks that coupling by moving the configuration source to an external trust boundary that is harder to remove quickly.
ClickFix, by contrast, is not about transport durability. It is about convincing the target to perform the malicious action themselves, usually by following a fake verification, update, or troubleshooting prompt. The abuse is social engineering, not hosting resilience.
This distinction matters operationally. A defender may detect ClickFix through user interaction patterns, clipboard abuse, or suspicious command invocation, while EtherHiding is more likely to show up as unusual web requests, blockchain lookups, or a loader that fetches instructions from a nontraditional source.
What defenders should look for when both appear together
When ClickFix and EtherHiding appear in the same chain, the visible web page is only part of the problem. The real security issue is the combination of user-driven execution and durable remote configuration, which can make the campaign harder to disrupt with ordinary web takedowns.
A practical MITRE ATLAS adversarial AI threat matrix style of thinking helps here even though the primary subject is browser abuse, because the same logic applies: map the attacker’s delivery path, execution trigger, and persistence layer separately.
For browser-based campaign analysis, CISA threat guidance is useful for pattern recognition and response coordination, especially when the lure, payload host, and downstream infrastructure are all changing quickly.
Risk and Threat Considerations
These chains are risky because they blend human deception with infrastructure resilience. ClickFix can turn a single successful prompt into code execution, and EtherHiding can keep the kit functioning after defenders remove the obvious hosting layer.
Failure mechanism: The victim is induced to run attacker-supplied instructions, while the payload location or configuration is fetched from a resilient external source that is not controlled by the compromised website alone.
Impact: Campaigns become harder to contain, more resistant to takedown, and more likely to reappear across fresh domains, making detection and cleanup slower than in a conventional web-hosted lure.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while OWASP ASVS and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1204 — User Execution | ClickFix relies on the victim running attacker-supplied instructions. |
| T1105 — Ingress Tool Transfer | Browser chains often fetch payloads or loaders from remote infrastructure. | |
| T1583 — Acquire Infrastructure | EtherHiding uses infrastructure choices that improve campaign durability. | |
| Recommendation — Hunt for user-execution prompts that trigger malicious code or commands. Monitor for staged payload retrieval from unusual external sources. Track attacker infrastructure patterns and block repeat delivery endpoints. | ||
| OWASP ASVS | V16 — Security Logging and Error Handling | Browser-based lure chains need telemetry to detect execution handoff and follow-on fetches. |
| Recommendation — Verify logging captures command handoff and remote fetch activity. | ||
| CIS Controls v8 | CIS-9 — Email and Web Browser Protections | The subject is a browser-based attack chain that begins with web-delivered social engineering. |
| Recommendation — Strengthen browser protections and filter suspicious web-delivered prompts. | ||
Practitioner Guidance
What to verify: Treat any browser page that asks a user to paste, run, or verify a command as a high-risk execution point. Confirm whether the page is trying to move the user from web content into a shell, terminal, or run dialog, and whether the instructions reference an external source that is not part of the organisation’s normal software delivery path.
What good looks like: The browser security stack, endpoint telemetry, and web filtering should give you enough visibility to separate the lure from the infrastructure behind it. If you can only see the landing page but not the subsequent command execution or remote configuration fetch, you do not yet have a complete picture of the chain.
Practitioner takeaway: The right response is to analyze ClickFix as the execution trigger and EtherHiding as the durability layer, because stopping one without understanding the other usually leaves part of the attack chain intact.
Related resources from NHI Mgmt Group
- What is the difference between a browser-based attack and a traditional email phishing campaign?
- What is the difference between browser-level security and network-based web security for modern enterprise access?
- What is the difference between phishing-resistant MFA and Just-in-Time access in browser-based attack defence?
- What is the difference between direct command and control and relay-based command and control in advanced malware?