Microsoft Threat Intelligence
Microsoft Threat Intelligence has identified a cluster of compromised websites displaying ClickFix lures and using EtherHiding, a technique associated with the ClearFake campaign. An injected Base64-encoded JavaScript contacts a BNB Smart Chain RPC gateway to query a smart contract previously reported in connection with ClearFake to fetch next-stage instructions. Content stored in a smart contract is resistant to conventional takedown or sinkholing because only the owner of the cryptocurrency wallet that deployed it can make changes. Users are presented with a fake CAPTCHA that instructs them to open the Windows Run dialog, paste clipboard content, and press Enter to execute an attacker-supplied command under the guise of verification. We’re seeing multiple forms of command obfuscation and living-off-the-land abuse, including conhost, cmd, PowerShell, pcalua, mshta, rundll32, msiexec, curl, WMI, WebDAV, and scheduled tasks. Carets split keywords, environment variables hide interpreters, and Windows run headlessly or minimized. TerminalFix lures apply the same technique but direct users to Windows Terminal or PowerShell instead of the Run dialog. This campaign demonstrates that ClickFix and TerminalFix are a high-volume initial access technique. Microsoft reports campaigns targeting thousands of enterprise and consumer devices globally every day, while some malvertising chains can funnel visitors to scam pages. Numerous actors use the technique to deliver Lumma Stealer and other infostealers, RATs such as Xworm and AsyncRAT, loaders including MintsLoader, and remote management tools. A single successful execution can expose credentials, establish persistence, enable lateral movement, and create a path to human-operated ransomware and potential domain compromise. Microsoft recommends that organizations enable Microsoft Defender network, web, and cloud-delivered protection; restrict Run and command-line tools where not required; enable PowerShell script-block logging; and implement application control. Users should never paste commands from CAPTCHAs, browser errors, emails, ads, or unsolicited support pages into Run, Terminal, PowerShell, or Command prompt. Microsoft Defender XDR provides layered protection across the ClickFix attack chain. Defender SmartScreen and Defender for Office 365 help block malicious sites, links, attachments, and fake CAPTCHA lures, while Defender for Endpoint detects suspicious command execution and outbound connections through alerts like “Suspicious command in RunMRU registry”, “Possible ClickFix activity”, “Possible initial access from an emerging threat”. Microsoft Defender Antivirus blocks malicious command execution using detections such as Trojan:Win32/ClickFix.* and Trojan:Win32/TermFix.*. Treat these alerts as evidence of a potential initial access incident: isolate affected devices, investigate credential exposure and persistence, and hunt for related activity.