In a BlockBeats post dated August 7, Microsoft’s Threat Intelligence team said it had identified a set of compromised websites that use ClickFix and TerminalFix to lure attacks, and that they combined EtherHiding technology to access smart contracts via the BNB Smart Chain RPC gateway to obtain the next-stage malicious instructions. Since the malicious content is stored in on-chain smart contracts, only the wallet owners that deploy those contracts can modify them, making it difficult to remove them through traditional takedown or banning methods.


Microsoft points out that attackers will forge CAPTCHA verification pages,诱骗 users into opening the Windows "Run" window or Terminal, PowerShell, then pasting and executing malicious commands. During the attack, system tools such as conhost, PowerShell, mshta, rundll32, curl, WMI, and WebDAV are widely used for obfuscation and "Living-off-the-Land" attacks by making use of readily available resources.


Microsoft says that ClickFix and TerminalFix have become high-frequency initial infection methods, affecting thousands of enterprise and personal devices worldwide every day. They are used by multiple threat groups to spread malware such as Lumma Stealer, Xworm, AsyncRAT, and MintsLoader, and may further lead to credential theft, lateral movement, and ransomware attacks. Microsoft advises users not to copy and execute any commands in Windows “Run,” Terminal, PowerShell, or Command Prompt based on CAPTCHAs, webpage error messages, email or ad prompts.