Microsoft Warns of New Attack Scheme via BNB Smart Chain

3 Min Read Tags:

  • Microsoft has issued a warning about a new wave of ClickFix attacks.
  • Hackers are embedding malicious instructions within the BNB Smart Chain blockchain, impacting thousands of devices daily.
  • The infection occurs through fake CAPTCHA prompts that trick users into executing harmful commands.

New Cyber Threat: Microsoft Warns of Attacks via BNB Smart Chain

In a recent revelation, Microsoft has sounded the alarm on a sophisticated series of cyberattacks leveraging the BNB Smart Chain blockchain. The campaign, driven by techniques known as ClickFix and TerminalFix, affects thousands of corporate and consumer devices globally each day.

The Mechanics Behind the Attack

According to insights shared by Microsoft Threat Intelligence, compromised websites are displaying fake CAPTCHA challenges. These prompts deceive users into executing pre-prepared commands under the guise of standard verification processes. The malicious payload is stored within smart contracts on the BNB Smart Chain, making it difficult to intercept or eliminate using conventional methods.
The attack begins with an injected Base64-encoded JavaScript on compromised sites. This script communicates with an RPC gateway on the BNB Smart Chain to retrieve instructions from a smart contract previously associated with campaigns like ClearFake. By storing instructions in this manner, only the wallet owner can alter or remove them, adding a layer of complexity to mitigation efforts.

Exploiting Common Security Vulnerabilities

Upon visiting an affected webpage, users encounter deceptive CAPTCHA tests prompting them to open Windows Run, paste clipboard contents, and execute commands prepared by attackers. Microsoft strongly advises against inserting any commands from such suspicious sources into Run or Terminal interfaces.
Cybercriminals employ various tactics to obscure these commands using legitimate Windows system tools such as PowerShell, cmd, rundll32, and others. For instance, TerminalFix exploits similar social engineering techniques but specifically targets Windows Terminal or PowerShell instead.

Broader Implications for Cybersecurity

The ramifications of these attacks are significant. Once initial access is achieved through ClickFix or TerminalFix methodologies, attackers can deploy various types of malware including data stealers like Lumma Stealer and remote access trojans (RAT) such as Xworm and AsyncRAT. This infiltration could lead to credential theft and further network penetration.
For organizations looking to bolster their defenses against such threats, Microsoft recommends enabling comprehensive security measures including network and cloud protection via Microsoft Defender. Additionally, restricting access to command-line interfaces where unnecessary can mitigate potential vulnerabilities.
Overall, this development underscores an urgent need for heightened vigilance in cybersecurity practices across industries relying on blockchain technologies. As these threats evolve in sophistication and reach, staying informed about emerging attack vectors remains crucial for safeguarding sensitive data within decentralized networks.

OpenAI Faces Lawsuit From Man Saying ChatGPT Convinced Him He Is Jesus

Michael Lines sued OpenAI and CEO Sam Altman, alleging ChatGPT reinforced religious delusions during a 2025 manic episode ending in a March suicide attempt; OpenAI said it is reviewing the…

5 Min Read
Canary Capital Launches First US Spot TRX ETF With Staking

Canary Capital launched the Canary Staked TRX ETF on Cboe BZX under ticker TRXS on Sept. 9, 2026, offering direct TRX exposure and staking rewards.

5 Min Read
Anthropic Models 3 US Economic Scenarios Through 2030

Anthropic published a model outlining three scenarios for the U.S. economy through 2030, with its extreme scenario suggesting annual GDP growth could reach 15% alongside historically high unemployment.

7 Min Read
Robinhood CEO Says Companies Cannot Control Tokenization of Their Shares

In September 2026, Robinhood CEO Vlad Tenev said companies cannot prevent third-party products linked to their shares, defending 1:1 share-backed Stock Tokens after AMC CEO Adam Aron challenged their legality.

5 Min Read
Germany Will Change Crypto-Asset Tax Rules in 2027, Media Reports

Germany’s draft crypto tax reforms would from Jan. 1, 2027, tax profits on covered assets acquired after Dec. 31, 2026, regardless of holding period, while platforms would begin withholding tax…

5 Min Read