Cybersecurity experts at Microsoft have uncovered a concerning trend where hackers are using the BNB Smart Chain to deploy a sophisticated malware campaign known as ClickFix. This campaign exploits legitimate websites to deliver malicious code, posing a significant threat to unsuspecting users.
According to Microsoft Threat Intelligence, attackers have been injecting JavaScript into compromised websites, which then connects to a smart contract on the BNB blockchain. This method allows hackers to retrieve malicious instructions, complicating traditional defensive measures typically employed against malware.
Once a user visits a compromised site, they are confronted with a fake CAPTCHA page that misleads them into executing commands. This method relies on victims unknowingly running the malware themselves by instructing them to open the Windows Run dialog, paste a command, and hit Enter. This deceptive tactic is part of the ClickFix methodology, while a variant known as TerminalFix directs users to Windows Terminal or PowerShell.
Consequences of Infection
After falling victim to this malicious scheme, infected devices can have various forms of malware installed, including Lumma Stealer, XWorm, AsyncRAT, and MintsLoader. These programs are designed to harvest sensitive information such as passwords, browser data, and cryptocurrency wallet information, granting attackers persistent access to the affected systems.
Furthermore, Microsoft warns that compromised devices could become prime targets for ransomware attacks, where attackers take manual control of a network before encrypting files for extortion.
The use of blockchain technology for malicious purposes is not unprecedented. In the past, various ransomware strains have utilized cryptocurrencies to establish command-and-control servers, with notable examples including Cerber ransomware and the Glupteba botnet. Recent research also exposed Omnistealer using multiple blockchains, including BNB, to steal credentials and crypto wallet data.
This isn’t Microsoft’s first warning concerning cryptocurrency-related security threats this year. Earlier, the company flagged clipboard hijacking campaigns that swapped copied wallet addresses with those controlled by attackers, alongside reports of cryptojacking campaigns driven by SEO poisoning.
Importantly, while the BNB Chain itself remains secure from compromise, attackers are exploiting its decentralized nature to host malicious instructions that are difficult to eliminate.
Protecting Yourself
In light of these revelations, Microsoft urges users to refrain from pasting commands from CAPTCHA pages, pop-ups, emails, or unknown websites, emphasizing that legitimate CAPTCHA systems will never request such actions.
For organizations, Microsoft recommends implementing PowerShell logging, utilizing application controls, and restricting the use of unnecessary command-line tools to bolster defenses against these sophisticated attacks.
