
Microsoft says ClickFix and TerminalFix lures are pulling malware instructions from BNB Smart Chain smart contracts through public RPC gateways, creating command infrastructure that is difficult to remove without disrupting legitimate network use.
Microsoft says attackers are using compromised websites, fake CAPTCHA pages and TerminalFix lures to trick users into running malicious commands that then fetch instructions from BNB Smart Chain smart contracts through public RPC gateways. The ClickFix and EtherHiding-style campaigns target thousands of enterprise and consumer devices each day, turning ordinary blockchain reads into resilient command infrastructure that is difficult to remove without affecting legitimate network activity. The company said the technique does not exploit BNB Smart Chain itself. Instead, it stores next-stage malware logic in on-chain data that can persist as long as the contract remains available, allowing the same contract to be reused across multiple infected sites. Microsoft said the campaigns can deliver Lumma Stealer, XWorm, AsyncRAT, MintsLoader and remote management tools, while defenders are left relying on endpoint detections, browser and wallet safeguards, and selective blocking because there is no simple kill switch for malicious contracts.