Key Takeaways: Microsoft Threat Intelligence has traced a malware campaign that hides attack commands inside BNB Chain smart contracts, infecting thousands of Windows devices daily.
Key Takeaways: Microsoft Threat Intelligence has traced a malware campaign that hides attack commands inside BNB Chain smart contracts, infecting thousands of Windows devices daily.

Microsoft Threat Intelligence has traced a malware campaign that hides attack commands inside BNB Chain smart contracts, infecting thousands of Windows devices daily.
Microsoft Threat Intelligence has identified a malware campaign storing attack commands in BNB Chain smart contracts, infecting thousands of Windows systems daily across corporate networks and consumer devices.
"This campaign demonstrates that ClickFix and TerminalFix are a high-volume initial access technique," Microsoft researchers wrote in a post on X on Thursday. "Microsoft reports campaigns targeting thousands of enterprise and consumer devices globally every day."
The operation, tracked as ClickFix and TerminalFix, uses a technique called EtherHiding. Malicious JavaScript injected into compromised websites queries a BNB Smart Chain RPC gateway to retrieve instructions from a contract previously linked to the ClearFake campaign. Victims see a counterfeit CAPTCHA prompt urging them to open the Windows Run dialog, paste pre-loaded clipboard content, and execute it. A variation called TerminalFix directs users to Windows Terminal or PowerShell instead.
Because only the wallet that deployed the contract can modify its contents, conventional takedown methods such as server seizures or sinkholing are ineffective. The instructions persist as long as the BNB Chain operates and the contract remains funded, allowing the same contract to be reused across multiple compromised sites.
How the infection chain works
Once the pasted command runs, the malware abuses legitimate Windows components including PowerShell, cmd, mshta, rundll32, msiexec, and scheduled tasks. Obfuscation methods further conceal activity: caret characters break up keywords, environment variables hide interpreters, and processes launch in minimized windows.
Observed payloads include the Lumma Stealer for credential theft, remote-access tools such as Xworm and AsyncRAT, and the MintsLoader for delivering further malware. Successful infections enable password harvesting, long-term system access, lateral movement within networks, and eventual deployment of human-operated ransomware that can jeopardize entire domains.
Blockchain as command-and-control infrastructure
The use of blockchain infrastructure for malware command-and-control is not new. In 2016, the Cerber ransomware began using Bitcoin transactions to locate its command-and-control servers. Between 2019 and 2021, the Glupteba botnet used the Bitcoin blockchain to find backup servers when its primary infrastructure went offline. In September 2023, ClearFake adopted EtherHiding on BNB Chain. In April 2026, researchers discovered Omnistealer using TRON, Aptos, and BNB Chain to steal credentials and crypto wallet data.
The disclosure follows a June 2026 Microsoft report on CryptoBandits, a clipper malware that monitored the clipboard for cryptocurrency addresses and swapped them with attacker-controlled ones.
Defense and forward outlook
Microsoft recommends organizations restrict unnecessary command-line utilities, enable PowerShell script-block logging, apply application-control policies, and activate full Defender protections covering network, web, and cloud threats. Microsoft Defender XDR offers multi-stage detection: SmartScreen and Defender for Office 365 can intercept malicious domains and fraudulent CAPTCHA pages early, while Defender for Endpoint flags suspicious command patterns and unusual outbound traffic.
End users should never paste commands from CAPTCHAs, browser errors, emails, ads, or unsolicited support pages into Run, Terminal, PowerShell, or the command prompt.
The findings come as BNB Chain pursues an ambitious technical roadmap. In July, the network unveiled plans for a new layer-1 blockchain designed for high-frequency trading, automated payments, and AI-driven transactions, with a testnet expected by the end of 2026 and a mainnet launch in early 2027. BNB traded at $602.15, up 1.67 percent, as of Aug. 8, according to CryptoRank data. While the malware issue is not unique to BNB Chain, the campaign highlights the growing challenge of blockchain-enabled cyber threats that resist traditional takedown methods.
This article is for informational purposes only and does not constitute investment advice.