Skip to main content
AVOID.NET

ClickFix BNB Chain EtherHiding Malware Campaign

avoid.net/clickfix-bnb-chain-etherhiding-malware-campaign0/100·91% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·4FL9c9…nCiE

Summary

An active malware campaign, publicly disclosed by Microsoft Threat Intelligence on August 7, 2026, combines ClickFix-style fake CAPTCHA social engineering with the EtherHiding technique to store malicious payload instructions inside BNB Smart Chain smart contracts. Because the payload hosting is on-chain and can only be modified by the deployer's private key, traditional DNS and hosting takedowns are ineffective against the attack infrastructure. Deployed payloads include information stealers, remote access trojans, and a crypto clipboard hijacker (CryptoBandits) that silently replaces copied wallet addresses with attacker-controlled ones every 500 milliseconds.

Connected Entities

3 entities · 60 linked investigations
Organizations
Protocols
ClickFix BNB Chain EtherHiding Malware Campaign
Relationships
  • ClickFix BNB Chain EtherHiding Malware Campaignmentioned withBinance(70%)
  • ClickFix BNB Chain EtherHiding Malware Campaignmentioned withAmazon(60%)

Connected Through

2 shared actors · 527 investigations

Distinct actors this investigation shares with others — holders, traders, and named parties. Shared infrastructure (exchanges, pools) is excluded.

Have evidence about ClickFix BNB Chain EtherHiding Malware Campaign?

Timeline(9 events)

August 2023

ClearFake campaign begins using EtherHiding technique on BNB Smart Chain, storing malicious payload JavaScript inside on-chain smart contracts. Guardz researchers later document this as the first known EtherHiding campaign.

The Hacker News

16 October 2023

The Hacker News and Guardz publicly document the EtherHiding technique for the first time, describing it as 'the next level of bulletproof hosting' and attributing it to the ClearFake campaign targeting WordPress sites.

The Hacker News

October 2025

Google Threat Intelligence Group (GTIG) reports that DPRK-linked threat actor UNC5342 has adopted the EtherHiding technique in fake job interview social engineering campaigns targeting software developers, marking the first documented nation-state use of the technique.

Google Cloud Blog

February 2026

CryptoBandits malware campaign begins activity, distributing clipboard-hijacking and USB-worm components via malicious .lnk payloads. Microsoft later identifies the campaign as active from at least February 2026.

Microsoft Security Blog

April 2026

Researchers discover the Omnistealer campaign using TRON, Aptos, and BNB Chain blockchains for on-chain payload delivery to steal credentials, cloud account data, passwords, and cryptocurrency wallet contents, demonstrating multi-chain expansion of the EtherHiding model.

Decrypt

17 June 2026

Microsoft Security Blog publicly discloses the CryptoBandits malware: a clipboard hijacker polling every 500 milliseconds for cryptocurrency wallet addresses, propagating via USB worm, and routing C2 traffic through Tor. Trojan:Win32/CryptoBandits.A detection name assigned.

Microsoft Security Blog

7 August 2026

Microsoft Threat Intelligence publicly discloses the active ClickFix + EtherHiding + BNB Chain campaign, stating it targets thousands of enterprise and consumer Windows devices globally every day. Payloads identified include Lumma Stealer, XWorm, AsyncRAT, and MintsLoader. Detections Trojan:Win32/ClickFix.* and Trojan:Win32/TermFix.* named.

crypto.news / Decrypt / Crypto Economy

7 August 2026

Huntress researchers separately document a Go-based macOS infostealer delivered via ClickFix attacks, capable of partially redirecting cryptocurrency transactions without fully emptying wallets to evade detection.

The Hacker News

8 August 2026

The Hacker News reports over 250 ClickFix domains using browser fingerprinting to serve platform-specific macOS malware lures, indicating campaign infrastructure has scaled to hundreds of distinct lure domains.

The Hacker News
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (3 events). 17 of 18 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 8/8/2026, 11:15:55 PM

last updated: 8/10/2026, 1:14:52 PM

5 views

avoid.net — verified advice for a post-truth world