ClickFix Malware Exploits BNB Chain Contracts to Outsmart Security Measures
Microsoft has issued a security alert about a large-scale ClickFix malware operation that uses BNB Chain smart contracts to deliver attack payloads. This sophisticated campaign affects thousands of corporate and individual machines globally every day by exploiting compromised web properties.
Cybercriminals merge deceptive CAPTCHA interfaces with blockchain technology, creating significant challenges for conventional removal strategies. By embedding Base64-encoded JavaScript within vulnerable websites and routing execution toward BNB Smart Chain systems, the malicious script communicates with blockchain RPC endpoints and retrieves additional instructions from deployed smart contracts.
Microsoft's investigation connected this contract infrastructure to systems previously used in the ClearFake malware operation. Utilizing blockchain storage provides threat actors with significant resilience against disruption, as standard server seizures prove ineffective at removing embedded instructions.