News Report Technology
August 07, 2026

Microsoft Threat Intelligence: ClickFix Attackers Use Blockchain Smart Contracts To Evade Takedowns

In Brief

Microsoft warns of evolving ClickFix threats using on-chain smart contract storage and browser fingerprinting to target Windows and macOS systems.

Microsoft Threat Intelligence: ClickFix Attackers Use Blockchain Smart Contracts To Evade Takedowns

Microsoft Threat Intelligence has published findings on an evolving ClickFix attack campaign that now leverages blockchain infrastructure and sophisticated browser fingerprinting to compromise both Windows and macOS systems at scale.

The Windows-focused operations employ EtherHiding, a technique that stores malicious commands directly within smart contracts on the BNB Smart Chain. Attackers inject Base64-encoded JavaScript into compromised websites that queries these contracts via RPC gateways to fetch next-stage instructions. 

Because the payload resides on-chain, it cannot be removed through conventional takedown or sinkholing methods—only the deploying cryptocurrency wallet owner can alter its contents. 

Victims are presented with fake CAPTCHAs that instruct them to open the Windows Run dialog and paste attacker-supplied commands. Execution chains abuse native utilities including PowerShell, mshta, rundll32, msiexec, and curl, often employing caret splitting and environment variable obfuscation to evade detection. Microsoft reports that these campaigns target thousands of enterprise and consumer devices globally each day, delivering payloads such as Lumma Stealer, Xworm, AsyncRAT, and MintsLoader. 

A single successful infection can expose credentials, establish persistence, enable lateral movement, and create pathways to human-operated ransomware.

macOS Operations Deploy Anti-Analysis Fingerprinting Gates

In parallel, Microsoft tracked a macOS ClickFix cluster that has shifted from openly serving malicious terminal commands to hiding them behind server-side browser fingerprinting gates. The operation spans more than 250 domains, many following algorithmic naming patterns such as “filewordword” constructions. When visitors arrive, a lightweight JavaScript profiling routine collects browser attributes, WebGL GPU signals, timezone offsets, and iframe context, then submits this fingerprint to the server for evaluation. 

Requests that fail these checks—such as those from sandboxes, virtual machines, or non-macOS browsers—receive benign decoy pages or blank content, while genuine macOS visitors are shown a counterfeit “Verified Publisher” download page with a malicious terminal command. This traffic distribution system delivers information stealers including MacSync and Atomic Stealer, which target keychain data, browser credentials, cryptocurrency wallets, and SSH keys. 

The fingerprinting techniques themselves are not novel, but their integration into ClickFix infrastructure complicates automated detection and analysis by serving malicious content only to selectively qualified victims.

Disclaimer

In line with the Trust Project guidelines, please note that the information provided on this page is not intended to be and should not be interpreted as legal, tax, investment, financial, or any other form of advice. It is important to only invest what you can afford to lose and to seek independent financial advice if you have any doubts. For further information, we suggest referring to the terms and conditions as well as the help and support pages provided by the issuer or advertiser. MetaversePost is committed to accurate, unbiased reporting, but market conditions are subject to change without notice.

About The Author

Alisa, a dedicated journalist at the MPost, specializes in crypto, AI, investments, and the expansive realm of Web3. With a keen eye for emerging trends and technologies, she delivers comprehensive coverage to inform and engage readers in the ever-evolving landscape of digital finance.

More articles
Alisa Davidson
Alisa Davidson

Alisa, a dedicated journalist at the MPost, specializes in crypto, AI, investments, and the expansive realm of Web3. With a keen eye for emerging trends and technologies, she delivers comprehensive coverage to inform and engage readers in the ever-evolving landscape of digital finance.

Hot Stories
Join Our Newsletter.
Latest News

How Minmax Is Building The Professional AI Trading Terminal Prediction Markets Still Lack In 2026

Minmax processed roughly $100,000 in volume in the first three days of June, most of it through ...

Know More

The Calm Before The Solana Storm: What Charts, Whales, And On-Chain Signals Are Saying Now

Solana has demonstrated strong performance, driven by increasing adoption, institutional interest, and key partnerships, while facing potential ...

Know More
Read More
Read more
Top 10 Enterprise Platforms Connecting Traditional Banking With Digital Assets
Top Lists Business Technology
Top 10 Enterprise Platforms Connecting Traditional Banking With Digital Assets
August 7, 2026
Top 10 Platforms Enabling Programmable Financial Contracts
Top Lists Business Technology
Top 10 Platforms Enabling Programmable Financial Contracts
August 6, 2026
Sui To Deploy Quantum-Safe Vaults On Mainnet In 2026 As Post-Quantum Threat Timeline Accelerates
News Report Technology
Sui To Deploy Quantum-Safe Vaults On Mainnet In 2026 As Post-Quantum Threat Timeline Accelerates
August 6, 2026
Blockchain Infrastructure Firm Plume Joins DTCC Group To Advance Institutional Tokenized Securities Settlement
Business News Report Technology
Blockchain Infrastructure Firm Plume Joins DTCC Group To Advance Institutional Tokenized Securities Settlement
August 6, 2026