Microsoft Threat Intelligence Flags ClickFix and EtherHiding Malware Campaign

Microsoft Threat Intelligence Flags ClickFix and EtherHiding Malware Campaign

N
News Editor
2026-08-07 02:52:57
Microsoft Threat Intelligence has flagged a cluster of compromised websites that are spreading malware through two abuse techniques: ClickFix and EtherHiding. The campaign reportedly targets thousands of enterprise and consumer devices every day. Attackers inject Base64-encoded JavaScript into affected pages, which then reaches out to BNB Smart Chain RPC gateways and pulls the next-stage instructions stored on a smart contract. Because only the deployer wallet can modify that contract, conventional takedown methods are difficult to apply. To get the infection going, victims are shown a fake CAPTCHA and tricked into opening the Run dialog, pasting clipboard contents, and executing attacker-supplied commands. Microsoft flagged the abuse of system tools such as conhost, cmd, PowerShell and mshta, along with command obfuscation. If the chain completes, credential exposure, persistence, lateral movement and ransomware attacks become possible. Microsoft recommends that organizations enable layered Defender protection, restrict command-line tools and enable PowerShell script logging, while users should not paste unrecognized commands into the Run box or a terminal.

Microsoft Threat Intelligence said on X that a cluster of compromised websites is pushing malware through two abuse techniques: ClickFix and EtherHiding. The campaign reportedly targets thousands of enterprise and consumer devices worldwide each day.

Next-stage commands pulled from BNB Smart Chain

The attackers inject Base64-encoded JavaScript into the affected sites. That script connects to BNB Smart Chain RPC gateways and pulls the next-stage instructions stored in a smart contract. Since only the deployer wallet can modify the contract's contents, conventional takedown methods are hard to pull off, Microsoft noted.

Fake CAPTCHA leads to a paste-and-run routine

The infection flow relies on a fake CAPTCHA that tricks users into opening the Run dialog, pasting clipboard content, and executing attacker-supplied commands. Microsoft listed several system utilities abused along the way, including conhost, cmd, PowerShell and mshta, plus command obfuscation to hide what the commands actually do.

What happens after execution

Once the chain runs through, a device can end up with exposed credentials, a persistent foothold, lateral movement and, in the worst case, a ransomware attack. Microsoft advises organizations to enable layered Defender protection, restrict command-line tools, and turn on PowerShell script logging. End users, meanwhile, should avoid pasting unverified commands into the Run box or a terminal.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
610

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.