PANews
PANews|Aug 07, 2026 02:52
[Microsoft: ClickFix attack campaign leverages BNB Smart Chain to host malicious instructions, targeting thousands of devices daily] Microsoft Threat Intelligence posted on the X platform, revealing that a cluster of compromised websites is using ClickFix and EtherHiding techniques to distribute malware. The attack campaign targets thousands of enterprise and consumer devices globally every day. Attackers inject Base64-encoded JavaScript to interact with the BNB Smart Chain (BNB Smart Chain) RPC gateway, retrieving the next-stage instructions stored in smart contracts. Since the contract content can only be modified by the deployer's wallet, traditional takedown methods are difficult to implement. The attack deceives users with fake CAPTCHA prompts, tricking them into opening a run dialog box, pasting clipboard content, and executing attacker commands. It also involves the abuse of various system tools such as conhost, cmd, PowerShell, mshta, and employs command obfuscation techniques.
+5
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads