Loading...
Loading...
quote: 🚨GoPlus Community Alert Microsoft Threat Intelligence has identified malicious websites abusing BNB Chain RPC gateways to fetch live malicious instructions from on-chain smart contracts, then using fake CAPTCHA / “browser repair” prompts to socially engineer users into running them. These ClickFix / TerminalFix campaigns are hitting thousands of enterprise and consumer devices worldwide every day. Attack chain: 1. Attackers compromise legitimate sites and inject JS that displays fake CAPTCHA or “fix your browser” screens. 2. The page doesn’t hardcode the payload — it queries a BNB Chain RPC endpoint and dynamically pulls the next-stage commands from a smart contract. 3. Users are instructed to open Win+R / Terminal / PowerShell and paste a “verification” or “repair” command — which actually executes the freshly fetched on-chain payload. 4. Successful execution frequently leads to Lumma and other info-stealers, destructive malware, or full remote-access tools. Immediate advice: 1️⃣Any page that tells you to press Win+R, open Terminal/PowerShell/cmd, and paste something is malicious. Close it immediately. 2️⃣Never trust “CAPTCHA failed — run this command to fix”, “browser error — execute this script”, or “support needs you to paste a command in the terminal”. 3️⃣Don’t copy, don’t paste, don’t run. Close the tab and clear recent downloads if needed. 4️⃣If you already ran the command: disconnect from the network right away and change critical passwords (email, SSO, company IM, browser sync, VPN, password manager) from a clean device. | Microsoft Threat Intelligence has identified a cluster of compromised websites displaying ClickFix lures and using EtherHiding, a technique associated with the ClearFake campaign. An injected Base64-encoded JavaScript contacts a BNB Smart Chain RPC gateway to query a smart contract previously reported in connection with ClearFake to fetch next-stage instructions. Content stored in a smart contract is resistant to conventional takedown or sinkholing because only the owner of the cryptocurrency wallet that deployed it can make changes. Users are presented with a fake CAPTCHA that instructs them to open the Windows Run dialog, paste clipboard content, and press Enter to execute an attacker-supplied command under the guise of verification. We’re seeing multiple forms of command obfuscation and living-off-the-land abuse, including conhost, cmd, PowerShell, pcalua, mshta, rundll32, msiexec, curl, WMI, WebDAV, and scheduled tasks. Carets split keywords, environment variables hide interpreters, and Windows run headlessly or minimized. TerminalFix lures apply the same technique but direct users to Windows Terminal or PowerShell instead of the Run dialog. This campaign demonstrates that ClickFix and TerminalFix are a high-volume initial access technique. Microsoft reports campaigns targeting thousands of enterprise and consumer devices globally every day, while some malvertising chains can funnel visitors to scam pages. Numerous actors use the technique to deliver Lumma Stealer and other infostealers, RATs such as Xworm and AsyncRAT, loaders including MintsLoader, and remote management tools. A single successful execution can expose credentials, establish persistence, enable lateral movement, and create a path to human-operated ransomware and potential domain compromise. Microsoft recommends that organizations enable Microsoft Defender network, web, and cloud-delivered protection; restrict Run and command-line tools where not required; enable PowerShell script-block logging; and implement application control. Users should never paste commands from CAPTCHAs, browser errors, emails, ads, or unsolicited support pages into Run, Terminal, PowerShell, or Command prompt. Microsoft Defender XDR provides layered protection across the ClickFix attack chain. Defender SmartScreen and Defender for Office 365 help block malicious sites, links, attachments, and fake CAPTCHA lures, while Defender for Endpoint detects suspicious command execution and outbound connections through alerts like “Suspicious command in RunMRU registry”, “Possible ClickFix activity”, “Possible initial access from an emerging threat”. Microsoft Defender Antivirus blocks malicious command execution using detections such as Trojan:Win32/ClickFix.* and Trojan:Win32/TermFix.*. Treat these alerts as evidence of a potential initial access incident: isolate affected devices, investigate credential exposure and persistence, and hunt for related activity.
Source:https://x.com/GoPlusSecurity/status/2086444888296673421
Impact Score