Skip to main content
Sign in

ClickFix BNB Chain EtherHiding Malware Campaign

avoid.net/clickfix-bnb-chain-etherhiding-malware-campaign0/100·91% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Summary

An active malware campaign, publicly disclosed by Microsoft Threat Intelligence on August 7, 2026, combines ClickFix-style fake CAPTCHA social engineering with the EtherHiding technique to store malicious payload instructions inside BNB Smart Chain smart contracts. Because the payload hosting is on-chain and can only be modified by the deployer's private key, traditional DNS and hosting takedowns are ineffective against the attack infrastructure. Deployed payloads include information stealers, remote access trojans, and a crypto clipboard hijacker (CryptoBandits) that silently replaces copied wallet addresses with attacker-controlled ones every 500 milliseconds.

Connected Entities

1 entities · 10 linked investigations
Protocols
ClickFix BNB Chain EtherHiding Malware Campaign
Relationships
    Have evidence about ClickFix BNB Chain EtherHiding Malware Campaign?

    Timeline(9 events)

    2023-08-01

    ClearFake campaign begins using EtherHiding technique on BNB Smart Chain, storing malicious payload JavaScript inside on-chain smart contracts. Guardz researchers later document this as the first known EtherHiding campaign.

    The Hacker News

    2023-10-16

    The Hacker News and Guardz publicly document the EtherHiding technique for the first time, describing it as 'the next level of bulletproof hosting' and attributing it to the ClearFake campaign targeting WordPress sites.

    The Hacker News

    2025-10-01

    Google Threat Intelligence Group (GTIG) reports that DPRK-linked threat actor UNC5342 has adopted the EtherHiding technique in fake job interview social engineering campaigns targeting software developers, marking the first documented nation-state use of the technique.

    Google Cloud Blog

    2026-02-01

    CryptoBandits malware campaign begins activity, distributing clipboard-hijacking and USB-worm components via malicious .lnk payloads. Microsoft later identifies the campaign as active from at least February 2026.

    Microsoft Security Blog

    2026-04-01

    Researchers discover the Omnistealer campaign using TRON, Aptos, and BNB Chain blockchains for on-chain payload delivery to steal credentials, cloud account data, passwords, and cryptocurrency wallet contents, demonstrating multi-chain expansion of the EtherHiding model.

    Decrypt

    2026-06-17

    Microsoft Security Blog publicly discloses the CryptoBandits malware: a clipboard hijacker polling every 500 milliseconds for cryptocurrency wallet addresses, propagating via USB worm, and routing C2 traffic through Tor. Trojan:Win32/CryptoBandits.A detection name assigned.

    Microsoft Security Blog

    2026-08-07

    Microsoft Threat Intelligence publicly discloses the active ClickFix + EtherHiding + BNB Chain campaign, stating it targets thousands of enterprise and consumer Windows devices globally every day. Payloads identified include Lumma Stealer, XWorm, AsyncRAT, and MintsLoader. Detections Trojan:Win32/ClickFix.* and Trojan:Win32/TermFix.* named.

    crypto.news / Decrypt / Crypto Economy

    2026-08-07

    Huntress researchers separately document a Go-based macOS infostealer delivered via ClickFix attacks, capable of partially redirecting cryptocurrency transactions without fully emptying wallets to evade detection.

    The Hacker News

    2026-08-08

    The Hacker News reports over 250 ClickFix domains using browser fingerprinting to serve platform-specific macOS malware lures, indicating campaign infrastructure has scaled to hundreds of distinct lure domains.

    The Hacker News
    Provenance & Audit Trail
    11 Wayback Archives

    Decision Log

    • #1publish⛓ pending8/8/2026, 11:16:05 PM
      hash: aQcz63gjyRNyFk1YRVhqNeySMjwCrE5WN7BtY4m9RGM

    11 of 18 cited source URLs have an Internet Archive snapshot.

    model: claude-sonnet-4-6

    generated: 8/8/2026, 11:15:55 PM

    last updated: 8/9/2026, 2:56:34 AM

    avoid.net — verified advice for a post-truth world