ClickFix Malware Campaign Uses BNB Chain Smart Contracts to Evade Takedowns
Microsoft has sounded the alarm on a widespread ClickFix malware campaign that's using BNB Chain smart contracts to evade takedown efforts. The campaign targets thousands of devices worldwide each day, compromising enterprise and consumer systems through compromised websites.
The attackers use fake CAPTCHA prompts to trick users into running attacker-controlled commands, which can deploy infostealers, RATs, loaders, and remote access software. ClickFix can also open the door to credential theft and ransomware operations.
Microsoft recommends that organizations strengthen their network, web, and cloud protection, as well as tighten controls for unnecessary command-line tools. Users should never paste commands from CAPTCHAs or suspicious emails.