Back to News
Microsoft Warns of ClickFix and TerminalFix Attacks Using EtherHiding on BNB Smart Chain
By Exbasi Intelligence
Sourced from Binance News
Microsoft's threat intelligence team said it has identified a group of compromised websites using ClickFix and TerminalFix to trick users into attacks, combined with EtherHiding technology to retrieve the next stage of malicious instructions through a BNB Smart Chain RPC gateway. According to BlockBeats On-chain Detection, the malicious content is stored in an on-chain smart contract, making it difficult to remove through traditional takedown or blocking methods because only the wallet owner that deployed the contract can modify it.Microsoft said attackers forge CAPTCHA verification pages to persuade users to open the Windows Run window, Terminal, or PowerShell, then paste and execute malicious commands. The attacks also rely on system tools such as conhost, PowerShell, mshta, rundll32, curl, WMI, and WebDAV for obfuscation and living-off-the-land activity.Microsoft said ClickFix and TerminalFix have become frequent initial intrusion methods, affecting thousands of enterprise and personal devices worldwide each day. The methods have been used by multiple threat groups to distribute malware including Lumma Stealer, Xworm, AsyncRAT, and MintsLoader, and could further lead to credential theft, lateral movement, and ransomware attacks. Microsoft advised users not to paste or run any commands in Windows Run, Terminal, PowerShell, or Command Prompt based on prompts from CAPTCHA pages, website errors, emails, or advertisements.