BNB Smart Chain Used in Sophisticated Attack Scheme Targeting Thousands Daily
A new wave of attacks is targeting thousands of devices worldwide every day, according to Microsoft Threat Intelligence. The attacks, known as ClickFix and TerminalFix, use compromised websites displaying fake CAPTCHAs to lure victims into running malicious code.
The attackers store instructions for the next stage of the attack in a smart contract on the BNB Smart Chain blockchain, making it difficult to remove using traditional methods. Once the victim runs the command, the attackers can install various types of malware, including infostealers, RAT trojans, and loaders.
Microsoft recommends that organizations enable Microsoft Defender network, web, and cloud protection, restrict access to Run and the command line where they are not needed, turn on PowerShell script block logging, and implement application control. The company stresses that users should not paste commands from CAPTCHAs or browser error messages into Windows Run, Terminal, PowerShell, or Command Prompt.