Microsoft flags ClickFix malware using BNB Chain to fetch attack instructions

Microsoft has warned of ClickFix attacks using BNB Chain smart contracts to infect thousands of devices every day. Summary Microsoft said ClickFix attacks are using BNB Chain smart contracts to deliver malware instructions. Fake CAPTCHA pages trick users into running attacker supplied commands on Windows devices. The campaign targets thousands of enterprise and consumer devices worldwide every day. Microsoft warned successful attacks can expose credentials and lead to ransomware deployment. According to Microsoft Threat Intelligence, a cluster of compromised websites has been using ClickFix lures together with the EtherHiding technique to deliver malware, with campaigns targeting thousands of enterprise and consumer devices worldwide each day. Microsoft Threat Intelligence has identified a cluster of compromised websites displaying ClickFix lures and using EtherHiding, a technique associated with the ClearFake campaign. An injected Base64-encoded JavaScript contacts a BNB Smart Chain RPC gateway to query a smart… pic.twitter.com/FOivGuUxVV — Microsoft Threat Intelligence (@MsftSecIntel) August 6, 2026 The security team said attackers inject Base64-encoded JavaScript into compromised websites. Instead of retrieving payload instructions from a traditional server, the script connects to a BNB Smart Chain RPC gateway and queries a smart contract previously linked to the ClearFake campaign. Because only the owner of the cryptocurrency wallet that deployed the contract can modify its contents, the instructions remain difficult to remove using conventional takedown or sinkholing methods. Microsoft said victims are shown a fake CAPTCHA asking them to verify they are human. Instead of completing a normal verification step, users are instructed to open the Windows Run dialog, paste clipboard content, and press Enter, executing an attacker-controlled command on their own systems. ClickFix campaign has used blockchain to deliver attack instructions While the fake CAPTCHA acts as the lure, the report said attackers rely on several command obfuscation methods to avoid detection after execution. Microsoft observed the abuse of Windows tools including conhost, cmd, PowerShell, pcalua, mshta, rundll32, msiexec, curl, WMI, WebDAV, and scheduled tasks. Researchers also identified multiple techniques designed to hide malicious commands. Caret characters split keywords, environment variables conceal interpreters, and Windows processes run in minimized or headless mode to reduce visibility during execution. Alongside ClickFix, Microsoft said attackers are also deploying TerminalFix lures. Rather than directing victims to the Windows Run dialog, TerminalFix instructs users to paste commands into Windows Terminal or PowerShell, using the same social engineering method to trigger the attack. You might also like: TrapDoor malware campaign steals crypto wallet data through fake developer tools The report described ClickFix and TerminalFix as high-volume initial access techniques. Microsoft said it is tracking campaigns targeting thousands of enterprise and consumer devices globally every day, while some malvertising chains also redirect users to scam pages before the malicious instructions are delivered.
عنوان اصلی (انگلیسی): Microsoft flags ClickFix malware using BNB Chain to fetch attack instructions
مشاهدهی خبر کامل در منبع ↗ بازگشت به سوییاین خلاصه بهصورت خودکار از کوینمارکتکپ ترجمه شده و ممکن است خطای ماشینی داشته باشد؛ صرفاً جهت اطلاعرسانی است و توصیهی معاملاتی نیست.