Microsoft Threat Intelligence: ClickFix Attackers Use Blockchain Smart Contracts To Evade Takedowns

07-Aug-2026 mpost.io
Microsoft Threat Intelligence: ClickFix Attackers Use Blockchain Smart Contracts To Evade Takedowns

Microsoft Threat Intelligence has published findings on an evolving ClickFix attack campaign that now leverages blockchain infrastructure and sophisticated browser fingerprinting to compromise both Windows and macOS systems at scale.

The Windows-focused operations employ EtherHiding, a technique that stores malicious commands directly within smart contracts on the BNB Smart Chain. Attackers inject Base64-encoded JavaScript into compromised websites that queries these contracts via RPC gateways to fetch next-stage instructions. 

Because the payload resides on-chain, it cannot be removed through conventional takedown or sinkholing methods—only the deploying cryptocurrency wallet owner can alter its contents. 

Victims are presented with fake CAPTCHAs that instruct them to open the Windows Run dialog and paste attacker-supplied commands. Execution chains abuse native utilities including PowerShell, mshta, rundll32, msiexec, and curl, often employing caret splitting and environment variable obfuscation to evade detection. Microsoft reports that these campaigns target thousands of enterprise and consumer devices globally each day, delivering payloads such as Lumma Stealer, Xworm, AsyncRAT, and MintsLoader. 

A single successful infection can expose credentials, establish persistence, enable lateral movement, and create pathways to human-operated ransomware.

macOS Operations Deploy Anti-Analysis Fingerprinting Gates

In parallel, Microsoft tracked a macOS ClickFix cluster that has shifted from openly serving malicious terminal commands to hiding them behind server-side browser fingerprinting gates. The operation spans more than 250 domains, many following algorithmic naming patterns such as “filewordword” constructions. When visitors arrive, a lightweight JavaScript profiling routine collects browser attributes, WebGL GPU signals, timezone offsets, and iframe context, then submits this fingerprint to the server for evaluation. 

Requests that fail these checks—such as those from sandboxes, virtual machines, or non-macOS browsers—receive benign decoy pages or blank content, while genuine macOS visitors are shown a counterfeit “Verified Publisher” download page with a malicious terminal command. This traffic distribution system delivers information stealers including MacSync and Atomic Stealer, which target keychain data, browser credentials, cryptocurrency wallets, and SSH keys. 

The fingerprinting techniques themselves are not novel, but their integration into ClickFix infrastructure complicates automated detection and analysis by serving malicious content only to selectively qualified victims.

The post Microsoft Threat Intelligence: ClickFix Attackers Use Blockchain Smart Contracts To Evade Takedowns appeared first on Metaverse Post.

Also read: Carbon Launches TradFi-Native On-Chain Derivatives Venue With 950+ Markets in One Account
WHAT'S YOUR OPINION?
Related News