Overview
- Microsoft disclosed Friday that researchers have observed a large ClickFix/TerminalFix campaign that targets thousands of enterprise and consumer Windows devices each day.
- Compromised websites inject Base64‑encoded JavaScript that queries BNB Smart Chain RPC gateways and reads attacker instructions from deployed smart contracts.
- Visitors see fake CAPTCHA pages that tell them to paste clipboard text into the Windows Run box, Terminal, or PowerShell so the clipboard command executes attacker‑supplied code.
- Successful execution installs info‑stealers, remote access trojans, and loaders such as Lumma Stealer, Xworm, AsyncRAT, and MintsLoader which can expose credentials, enable lateral movement, and lead to ransomware or domain compromise.
- Microsoft says conventional takedowns are ineffective because only the wallet controlling a smart contract can change its on‑chain content and it urges defenders to enable Defender protections, restrict Run/terminal access, enable PowerShell script‑block logging, enforce application control, and isolate any hosts showing ClickFix detections.