Microsoft Threat Intelligence: ClickFix Attackers Use Blockchain Smart Contracts To Evade Takedowns
In Brief
Microsoft warns of evolving ClickFix threats using on-chain smart contract storage and browser fingerprinting to target Windows and macOS systems.

Microsoft Threat Intelligence has published findings on an evolving ClickFix attack campaign that now leverages blockchain infrastructure and sophisticated browser fingerprinting to compromise both Windows and macOS systems at scale.
The Windows-focused operations employ EtherHiding, a technique that stores malicious commands directly within smart contracts on the BNB Smart Chain. Attackers inject Base64-encoded JavaScript into compromised websites that queries these contracts via RPC gateways to fetch next-stage instructions.
Because the payload resides on-chain, it cannot be removed through conventional takedown or sinkholing methods—only the deploying cryptocurrency wallet owner can alter its contents.
Victims are presented with fake CAPTCHAs that instruct them to open the Windows Run dialog and paste attacker-supplied commands. Execution chains abuse native utilities including PowerShell, mshta, rundll32, msiexec, and curl, often employing caret splitting and environment variable obfuscation to evade detection. Microsoft reports that these campaigns target thousands of enterprise and consumer devices globally each day, delivering payloads such as Lumma Stealer, Xworm, AsyncRAT, and MintsLoader.
A single successful infection can expose credentials, establish persistence, enable lateral movement, and create pathways to human-operated ransomware.
macOS Operations Deploy Anti-Analysis Fingerprinting Gates
In parallel, Microsoft tracked a macOS ClickFix cluster that has shifted from openly serving malicious terminal commands to hiding them behind server-side browser fingerprinting gates. The operation spans more than 250 domains, many following algorithmic naming patterns such as “filewordword” constructions. When visitors arrive, a lightweight JavaScript profiling routine collects browser attributes, WebGL GPU signals, timezone offsets, and iframe context, then submits this fingerprint to the server for evaluation.
Requests that fail these checks—such as those from sandboxes, virtual machines, or non-macOS browsers—receive benign decoy pages or blank content, while genuine macOS visitors are shown a counterfeit “Verified Publisher” download page with a malicious terminal command. This traffic distribution system delivers information stealers including MacSync and Atomic Stealer, which target keychain data, browser credentials, cryptocurrency wallets, and SSH keys.
The fingerprinting techniques themselves are not novel, but their integration into ClickFix infrastructure complicates automated detection and analysis by serving malicious content only to selectively qualified victims.
Disclaimer
In line with the Trust Project guidelines, please note that the information provided on this page is not intended to be and should not be interpreted as legal, tax, investment, financial, or any other form of advice. It is important to only invest what you can afford to lose and to seek independent financial advice if you have any doubts. For further information, we suggest referring to the terms and conditions as well as the help and support pages provided by the issuer or advertiser. MetaversePost is committed to accurate, unbiased reporting, but market conditions are subject to change without notice.
About The Author
Alisa, a dedicated journalist at the MPost, specializes in crypto, AI, investments, and the expansive realm of Web3. With a keen eye for emerging trends and technologies, she delivers comprehensive coverage to inform and engage readers in the ever-evolving landscape of digital finance.
More articles
Alisa, a dedicated journalist at the MPost, specializes in crypto, AI, investments, and the expansive realm of Web3. With a keen eye for emerging trends and technologies, she delivers comprehensive coverage to inform and engage readers in the ever-evolving landscape of digital finance.



