{"id":36650,"date":"2026-08-07T08:09:11","date_gmt":"2026-08-07T08:09:11","guid":{"rendered":"https:\/\/bitunikey.com\/news\/microsoft-flags-clickfix-malware-using-bnb-chain-to-fetch-attack-instructions\/"},"modified":"2026-08-07T08:09:44","modified_gmt":"2026-08-07T08:09:44","slug":"microsoft-flags-clickfix-malware-using-bnb-chain-to-fetch-attack-instructions","status":"publish","type":"post","link":"https:\/\/bitunikey.com\/news\/microsoft-flags-clickfix-malware-using-bnb-chain-to-fetch-attack-instructions\/","title":{"rendered":"Microsoft flags ClickFix malware using BNB Chain to fetch attack instructions"},"content":{"rendered":"<p><\/p>\n<div class=\"post-detail__content blocks\">\n<p class=\"is-style-lead\">Microsoft has warned of ClickFix attacks using BNB Chain smart contracts to infect thousands of devices every day.<\/p>\n<div id=\"cn-block-summary-block_5674c188fd0b91b9c9a48713eeb4c0fc\" class=\"cn-block-summary\">\n<div class=\"cn-block-summary__nav tabs\">\n        <span class=\"tabs__item is-selected\">Summary<\/span>\n    <\/div>\n<div class=\"cn-block-summary__content\">\n<ul class=\"wp-block-list\">\n<li>Microsoft said ClickFix attacks are using BNB Chain smart contracts to deliver malware instructions.<\/li>\n<li>Fake CAPTCHA pages trick users into running attacker supplied commands on Windows devices.<\/li>\n<li>The campaign targets thousands of enterprise and consumer devices worldwide every day.<\/li>\n<li>Microsoft warned successful attacks can expose credentials and lead to ransomware deployment.<\/li>\n<\/ul><\/div>\n<\/div>\n<p><!-- .cn-block-summary --><\/p>\n<p>According to Microsoft Threat Intelligence, a cluster of compromised websites has been using ClickFix lures together with the EtherHiding technique to deliver malware, with campaigns targeting thousands of enterprise and consumer devices worldwide each day.<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-x wp-block-embed-x\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Microsoft Threat Intelligence has identified a cluster of compromised websites displaying ClickFix lures and using EtherHiding, a technique associated with the ClearFake campaign. <\/p>\n<p>An injected Base64-encoded JavaScript contacts a BNB Smart Chain RPC gateway to query a smart\u2026 <a rel=\"nofollow\" target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/t.co\/FOivGuUxVV\">pic.twitter.com\/FOivGuUxVV<\/a><\/p>\n<p>\u2014 Microsoft Threat Intelligence (@MsftSecIntel) <a rel=\"nofollow\" target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/x.com\/MsftSecIntel\/status\/2085399393302176075?ref_src=twsrc%5Etfw\">August 6, 2026<\/a><\/p><\/blockquote>\n<\/div>\n<\/figure>\n<p>The security team said attackers inject Base64-encoded JavaScript into compromised websites. Instead of retrieving payload instructions from a traditional server, the script connects to a BNB Smart Chain RPC gateway and queries a smart contract previously linked to the ClearFake campaign.<\/p>\n<p>Because only the owner of the cryptocurrency wallet that deployed the contract can modify its contents, the instructions remain difficult to remove using conventional takedown or sinkholing methods.<\/p>\n<p>Microsoft said victims are shown a fake CAPTCHA asking them to verify they are human. Instead of completing a normal verification step, users are instructed to open the Windows Run dialog, paste clipboard content, and press Enter, executing an attacker-controlled command on their own systems.<\/p>\n<h2 class=\"wp-block-heading\">ClickFix campaign has used blockchain to deliver attack instructions<\/h2>\n<p>While the fake CAPTCHA acts as the lure, the report said attackers rely on several command obfuscation methods to avoid detection after execution. Microsoft observed the abuse of Windows tools including conhost, cmd, PowerShell, pcalua, mshta, rundll32, msiexec, curl, WMI, WebDAV, and scheduled tasks.<\/p>\n<p>Researchers also identified multiple techniques designed to hide malicious commands. Caret characters split keywords, environment variables conceal interpreters, and Windows processes run in minimized or headless mode to reduce visibility during execution.<\/p>\n<p>Alongside ClickFix, Microsoft said attackers are also deploying TerminalFix lures. Rather than directing victims to the Windows Run dialog, TerminalFix instructs users to paste commands into Windows Terminal or PowerShell, using the same social engineering method to trigger the attack.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p>\n<p>The report described ClickFix and TerminalFix as high-volume initial access techniques. Microsoft said it is tracking campaigns targeting thousands of enterprise and consumer devices globally every day, while some malvertising chains also redirect users to scam pages before the malicious instructions are delivered.<\/p>\n<h2 class=\"wp-block-heading\">Malware can lead to credential theft and ransomware attacks<\/h2>\n<p>According to the report, numerous threat actors have adopted the technique to distribute several malware families after gaining initial access. Microsoft identified Lumma Stealer and other information stealers, Xworm and AsyncRAT remote access trojans, MintsLoader, and remote management tools among the payloads delivered through ClickFix campaigns.<\/p>\n<p>Researchers warned that a single successful execution can expose credentials, establish persistence on infected systems, enable lateral movement across networks, and create a path for human-operated ransomware attacks and possible domain compromise.<\/p>\n<p>To reduce the risk, Microsoft recommended enabling Microsoft Defender network, web, and cloud-delivered protection, restricting access to the Windows Run dialog and other command-line tools where they are not required, enabling PowerShell script-block logging, and enforcing application control policies.<\/p>\n<p>The company also advised users not to paste commands from fake CAPTCHAs, browser error pages, advertisements, unsolicited support pages, or emails into Windows Run, Terminal, PowerShell, or Command Prompt because attackers increasingly rely on convincing users to execute malicious commands themselves.<\/p>\n<h2 class=\"wp-block-heading\">Defender detections target ClickFix activity<\/h2>\n<p>Microsoft said Microsoft Defender XDR provides layered protection across different stages of the attack chain. According to the company, Defender SmartScreen and Defender for Office 365 can help block malicious websites, phishing links, infected attachments, and fake CAPTCHA pages before users interact with them.<\/p>\n<p>The security platform also detects suspicious command execution and outbound connections using alerts including \u201cSuspicious command in RunMRU registry,\u201d \u201cPossible ClickFix activity,\u201d and \u201cPossible initial access from an emerging threat.\u201d<\/p>\n<p>Meanwhile, Microsoft Defender Antivirus identifies malicious command execution under detections such as Trojan:Win32\/ClickFix.* and Trojan:Win32\/TermFix.*. The company said organizations should treat these detections as possible indicators of an initial access incident, isolate affected devices, investigate potential credential theft and persistence mechanisms, and search for related activity across their environments.<\/p>\n<h2 class=\"wp-block-heading\">Previous Microsoft warning highlighted crypto-focused malware<\/h2>\n<p>The latest findings follow another Microsoft Threat Intelligence report published in June that described a Windows-based CryptoBandits clipper campaign active since February 2026.<\/p>\n<p>According to the report, the malware spread through malicious .lnk shortcut files, monitored the clipboard every 500 milliseconds for cryptocurrency wallet addresses, seed phrases, and private keys, and replaced copied wallet addresses with attacker-controlled ones.\u00a0<\/p>\n<p>Researchers also found the malware routing communications through the Tor network, creating scheduled tasks for persistence, capturing screenshots, and executing attacker-supplied code, effectively giving operators lightweight backdoor access.<\/p>\n<p>Microsoft said at the time that defenders should investigate combinations of suspicious behavior rather than isolated events, particularly when script engines launched tools such as curl, cmd.exe, or PowerShell alongside Tor-related traffic.<\/p>\n<p>The previous warning came as crypto-related malware campaigns continued to evolve. As previously reported by crypto.news, StilachiRAT targeted browser-based cryptocurrency wallets and monitored clipboard activity, while SparkCat searched screenshots for wallet seed phrases using image scanning. Binance also warned users about clipper malware designed to replace copied cryptocurrency wallet addresses with attacker-controlled alternatives.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p>\n<\/p><\/div>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft has warned of ClickFix attacks using BNB Chain smart contracts to infect thousands of devices every day. Summary Microsoft said ClickFix attacks are using BNB Chain smart contracts to&hellip;<\/p>\n","protected":false},"author":1,"featured_media":30647,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-36650","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cryptocurrency"],"_links":{"self":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts\/36650","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/comments?post=36650"}],"version-history":[{"count":1,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts\/36650\/revisions"}],"predecessor-version":[{"id":36651,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts\/36650\/revisions\/36651"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/media\/30647"}],"wp:attachment":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/media?parent=36650"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/categories?post=36650"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/tags?post=36650"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}