|

Microsoft Threat Intelligence: ClickFix Attackers Use Blockchain Smart Contracts To Evade Takedowns

Microsoft Threat Intelligence: ClickFix Attackers Use Blockchain Smart Contracts To Evade Takedowns
Microsoft Threat Intelligence: ClickFix Attackers Use Blockchain Smart Contracts To Evade Takedowns

Microsoft Threat Intelligence has printed findings on an evolving ClickFix assault marketing campaign that now leverages blockchain infrastructure and complicated browser fingerprinting to compromise each Windows and macOS techniques at scale.

The Windows-focused operations make use of EtherHiding, a way that shops malicious instructions instantly inside sensible contracts on the BNB Smart Chain. Attackers inject Base64-encoded JavaScript into compromised web sites that queries these contracts by way of RPC gateways to fetch next-stage directions. 

Because the payload resides on-chain, it can’t be eliminated by way of standard takedown or sinkholing strategies—solely the deploying cryptocurrency pockets proprietor can alter its contents. 

Victims are offered with pretend CAPTCHAs that instruct them to open the Windows Run dialog and paste attacker-supplied instructions. Execution chains abuse native utilities together with PowerShell, mshta, rundll32, msiexec, and curl, usually using caret splitting and setting variable obfuscation to evade detection. Microsoft studies that these campaigns goal 1000’s of enterprise and shopper units globally every day, delivering payloads akin to Lumma Stealer, Xworm, AsyncRAT, and MintsLoader. 

A single profitable an infection can expose credentials, set up persistence, allow lateral motion, and create pathways to human-operated ransomware.

macOS Operations Deploy Anti-Analysis Fingerprinting Gates

In parallel, Microsoft tracked a macOS ClickFix cluster that has shifted from overtly serving malicious terminal instructions to hiding them behind server-side browser fingerprinting gates. The operation spans greater than 250 domains, many following algorithmic naming patterns akin to “filewordword” constructions. When guests arrive, a light-weight JavaScript profiling routine collects browser attributes, WebGL GPU indicators, timezone offsets, and iframe context, then submits this fingerprint to the server for analysis. 

Requests that fail these checks—akin to these from sandboxes, digital machines, or non-macOS browsers—obtain benign decoy pages or clean content material, whereas real macOS guests are proven a counterfeit “Verified Publisher” obtain web page with a malicious terminal command. This visitors distribution system delivers data stealers together with MacSync and Atomic Stealer, which goal keychain information, browser credentials, cryptocurrency wallets, and SSH keys. 

The fingerprinting methods themselves will not be novel, however their integration into ClickFix infrastructure complicates automated detection and evaluation by serving malicious content material solely to selectively certified victims.

The put up Microsoft Threat Intelligence: ClickFix Attackers Use Blockchain Smart Contracts To Evade Takedowns appeared first on Metaverse Post.

Similar Posts