Microsoft Threat Intelligence has discovered a malware campaign utilizing the EtherHiding technique to store its malicious commands within BNB Chain smart contracts. The network, which just announced plans to build a new layer-1 specifically for high-frequency trading in July 2026, has apparently become an ideal place for hackers to plant permanent instructions. These commands are directly connected to an older malware campaign called ClearFake.
Although the commands are securely stored on the blockchain, access to the user’s computer still requires a manual step - and this is where the main trap lies.
ClickFix Tactics and Fake CAPTCHAs
This attack method does not force its way through system security; instead, it tricks users into opening the door themselves. JavaScript injected into compromised websites displays a fake CAPTCHA on the visitor’s screen. Unwary victims are then directed to open the Windows Run dialog, paste text from their computer’s clipboard, and press Enter.
The technique, named ClickFix, immediately retrieves commands from the BNB Chain contract once executed. In addition to ClickFix, hackers are also distributing another variant called TerminalFix. This variant guides users to open Windows Terminal or PowerShell instead of Windows Run. Both lead to the same outcome: the victim’s computer fetches and executes malicious instructions from the blockchain without being detected by standard security systems.
Why Hide Behind Smart Contracts?
The choice of BNB Chain as the command storage location is not without reason. Storing instructions on the blockchain makes the data nearly impossible for security authorities to delete or block. Only the crypto wallet controlling the contract has the right to modify or revoke its contents. This characteristic gives hackers a tactical advantage to maintain their attack infrastructure over the long term.
Using decentralized networks to support cybercrime continues an old pattern. In 2016, the Cerber ransomware already utilized the Bitcoin blockchain to operate. A similar trace was also seen in the Glupteba botnet, which was active from 2019 to 2021. The difference is that this campaign on BNB Chain is massive in scale, targeting thousands of enterprise and consumer devices worldwide every day.
Fatal Consequences at the End of the Command
Once the user presses Enter and the command is successfully executed, the impact immediately spreads throughout the system. The hackers gain permanent access to the victim’s device. From this point, they can expose passwords, steal sensitive data, and ultimately deploy ransomware to hold the entire computer’s contents hostage.
Faced with this threat, Microsoft advises organizations to immediately restrict the use of unnecessary command-line tools and enable logging features in PowerShell. For everyday internet users, vigilance remains the ultimate line of defense. If a website suddenly asks you to copy strange text and run it outside the browser window, close the page immediately.
Reported from Decrypt.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




