ClickFix Malware Campaigns Use BNB Chain Smart Contracts for Attack Instructions
Microsoft has sounded an alarm about ClickFix malware campaigns that use BNB Chain smart contracts to fetch attack instructions and infect thousands of devices every day.
The company said attackers are using compromised websites displaying fake CAPTCHA pages to trick users into running attacker-supplied commands on Windows devices. Once the command is executed, it opens up a path for credential theft and ransomware attacks.
Researchers found that the campaign targets both enterprise and consumer devices globally every day, with thousands of devices falling victim each day. The malware can expose credentials, establish persistence on infected systems, enable lateral movement across networks, and create a path for human-operated ransomware attacks.