Microsoft Flags ClickFix Malware Using BNB Chain to Evade Takedowns

Binance


Set as Google Preferred SourceFollow on Google News

TLDR

  • Microsoft says ClickFix attacks target thousands of devices worldwide each day.
  • BNB Chain smart contracts help attackers resist conventional malware takedowns.
  • Fake CAPTCHA prompts trick users into running attacker-controlled commands.
  • ClickFix can deploy infostealers, RATs, loaders, and remote access software.
  • Microsoft urges tighter Windows controls and stronger Defender protections.

Microsoft has flagged a widespread ClickFix malware campaign that uses BNB Chain smart contracts to distribute attack instructions. The campaign targets thousands of enterprise and consumer devices worldwide every day through compromised websites. Attackers combine fake CAPTCHA prompts with blockchain infrastructure, making traditional takedown efforts more difficult.

BNB Chain Smart Contracts Help ClickFix Resist Takedowns

Attackers inject Base64-encoded JavaScript into compromised websites before directing the code toward BNB Smart Chain infrastructure. The script contacts a blockchain RPC gateway and queries a smart contract for additional attack instructions. Microsoft linked the contract activity to infrastructure previously associated with the ClearFake malware campaign.

Blockchain storage gives attackers an important advantage because conventional server shutdowns cannot easily remove stored instructions. Only the wallet controlling the deployed smart contract can normally change its stored content. Security teams cannot simply seize or sinkhole a traditional command server to disrupt the campaign.

The websites then display fake CAPTCHA pages that claim users must complete a human verification process. Instead, victims receive instructions to open Windows Run and paste content already copied to their clipboard. Pressing Enter executes the attacker-controlled command directly on the affected Windows system.

Microsoft Finds Attackers Abusing Built-In Windows Tools

Microsoft found attackers using several legitimate Windows utilities after victims execute the commands. These tools include PowerShell, cmd, conhost, mshta, rundll32, msiexec, curl, WMI, and WebDAV. Attackers also use scheduled tasks to maintain access after the initial malware installation.

The campaign applies several obfuscation methods to reduce the visibility of malicious commands during execution. Attackers split keywords with caret characters and hide interpreters through environment variables. They also launch Windows processes in minimized or headless modes to keep suspicious activity away from users.


Betpanda


Microsoft also identified TerminalFix attacks using the same social engineering method with different command interfaces. TerminalFix directs victims toward Windows Terminal or PowerShell instead of the Windows Run dialog. Both techniques depend on convincing users to execute harmful commands themselves.

ClickFix Malware Opens Path to Credential Theft and Ransomware

Microsoft found several malware families delivered after attackers gain access through ClickFix or TerminalFix lures. Payloads include Lumma Stealer, Xworm, AsyncRAT, MintsLoader, other information stealers, and remote management software. These tools can steal credentials, maintain access, and provide attackers with greater control over compromised systems.

A successful infection can also allow attackers to move across connected corporate networks after stealing valid credentials. Threat actors may establish persistence before reaching other computers, accounts, or administrative resources. That access can eventually support ransomware operations or broader domain compromise inside affected organizations.

Microsoft recommends stronger network, web, and cloud protection alongside tighter controls for unnecessary command-line tools. Organizations should also enable PowerShell script-block logging and enforce application control policies across managed Windows environments. Users should never paste commands from CAPTCHAs, advertisements, browser errors, unsolicited support pages, or suspicious emails.

Microsoft Defender Targets ClickFix Attack Activity

Microsoft Defender XDR provides several detection layers across different stages of ClickFix and TerminalFix attacks. SmartScreen and Defender for Office 365 can block malicious websites, phishing links, attachments, and deceptive CAPTCHA pages. Defender for Endpoint can also identify suspicious command execution and unusual outbound network connections.

Microsoft Defender Antivirus uses dedicated detections for malicious ClickFix and TerminalFix command activity on Windows devices. Security teams should treat these detections as possible signs of an initial access incident. Administrators should isolate affected systems and investigate credential theft, persistence methods, and related activity across their networks.

The latest warning follows another Microsoft report covering the CryptoBandits malware campaign observed during 2026. That malware monitored Windows clipboards for cryptocurrency addresses, seed phrases, and private keys before replacing copied addresses. It also used Tor connections, scheduled tasks, screenshots, and remote code execution to maintain wider access.

 


Stop guessing and start investing with confidence. KnockoutStocks gives you the AI insights, market intelligence, and stock research you need to spot opportunities, cut through the noise, and make smarter investment decisions — all in one powerful platform.

Sign up today and get 50% OFF full access to our premium stock picks.

Simply use coupon code SPECIAL50 at checkout to claim your exclusive discount.





Source link

Bybit

Be the first to comment

Leave a Reply

Your email address will not be published.


*