Microsoft Flags ClickFix Malware Using BNB Chain to Evade Takedowns
TLDR
- Microsoft says ClickFix attacks target thousands of devices worldwide each day.
- BNB Chain smart contracts help attackers resist conventional malware takedowns.
- Fake CAPTCHA prompts trick users into running attacker-controlled commands.
- ClickFix can deploy infostealers, RATs, loaders, and remote access software.
- Microsoft urges tighter Windows controls and stronger Defender protections.
Microsoft has flagged a widespread ClickFix malware campaign that uses BNB Chain smart contracts to distribute attack instructions. The campaign targets thousands of enterprise and consumer devices worldwide every day through compromised websites. Attackers combine fake CAPTCHA prompts with blockchain infrastructure, making traditional takedown efforts more difficult.
BNB Chain Smart Contracts Help ClickFix Resist Takedowns
Attackers inject Base64-encoded JavaScript into compromised websites before directing the code toward BNB Smart Chain infrastructure. The script contacts a blockchain RPC gateway and queries a smart contract for additional attack instructions. Microsoft linked the contract activity to infrastructure previously associated with the ClearFake malware campaign.
โฆ Continue reading the full article at the original source below.

