ClickFix BNB Chain EtherHiding Malware Campaign
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·4FL9c9…nCiESummary
An active malware campaign, publicly disclosed by Microsoft Threat Intelligence on August 7, 2026, combines ClickFix-style fake CAPTCHA social engineering with the EtherHiding technique to store malicious payload instructions inside BNB Smart Chain smart contracts. Because the payload hosting is on-chain and can only be modified by the deployer's private key, traditional DNS and hosting takedowns are ineffective against the attack infrastructure. Deployed payloads include information stealers, remote access trojans, and a crypto clipboard hijacker (CryptoBandits) that silently replaces copied wallet addresses with attacker-controlled ones every 500 milliseconds.
Connected Entities
3 entities · 60 linked investigations- ClickFix BNB Chain EtherHiding Malware Campaign→mentioned with→Binance(70%)
- ClickFix BNB Chain EtherHiding Malware Campaign→mentioned with→Amazon(60%)
Connected Through
2 shared actors · 527 investigationsDistinct actors this investigation shares with others — holders, traders, and named parties. Shared infrastructure (exchanges, pools) is excluded.
- □Binanceorganizationalso inSiavash Kayvanpour·0Gurhan Kiziloz·0AI-Powered Crypto Phishing Infrastructure 2026·0EU MiCA Regulator Impersonation Scam Wave·0DOJ Pig Butchering $25M Forfeiture 2026·0YieldBlox Stellar Oracle Manipulation Exploit (Feb 2026)·0Q2 2026 Bridge Exploit Wave·0Blazar Token / John A. DeSalvo·0Miasma npm Supply Chain Attack (Red Hat)·0BonkDAO Treasury Governance Attack·0Indonesia Pig Butchering Syndicate — Live Model Operation (2025-2026)·0Mass Ethereum Address-Poisoning Wave (Dec 2025-Jan 2026)·0IRS Fake Digital Asset Compliance Portal Phishing Campaign 2026·0Voyager Digital·0Mastra AI npm Supply Chain Attack (June 2026)·0Lab·0Gurhan Kiziloz (BlockDAG Co-Founder)·0MEV Bot Scam — YouTube AI Trading Bot Campaign (2026)·0DSJEX / BG Wealth Sharing·0Ben 'BitBoy' Armstrong·0BitMart Exchange — Insolvency Claims and Frozen Withdrawals (August 2026)·0Huione Group (Haowang Guarantee)·0Google Coin / Fake Gemini AI Chatbot Presale Operation·0Chris Larsen·0BonkDAO Treasury Governance Attack (July 2026)·0Alameda Research·0Interpol Operation First Light 2026 — $123M Romance Scam Crypto Network·0fake Ledger Live app·0IRS Fake Digital Asset Compliance Portal Letter Campaign — 2026·0MiCA Transition Impersonation Scam Wave 2026·0MiCA Post-Deadline Impersonation Scam Cluster — ESMA/AMF Warning August 2026·0LAB / LABUSDT·0Bitcoin Latinum·0Aurum Foundation·0EU MiCA Post-Deadline Regulator Impersonation Scam Cluster·0Malone Lam·0MiCA Transition Impersonation Fraud Cluster (2026)·0Sam Bankman-Fried·0H2 2026 July Bridge Hack Wave — Seven Attacks, $M+ Lost·0July 2026 Bridge Hack Wave — Three Protocols, $35.6M, One Day·0Q2 2026 Record Crypto Hack Wave·0Ill Bloom Vulnerability·0OLPC Token / PancakeSwap OLPC-LABUBU Pool·0Q2 2026 DeFi Record Hack Wave·0Fake MetaMask Update Phishing Campaign (May 2026)·0Inferno Drainer·0Crypto DAO (BNB Chain Access-Control Exploit, July 2026)·0DPRK Crypto Theft H1 2026 (TRM Labs / Blockaid Report)·0EVM Cross-Chain Wallet-Drain Campaign (June 2026)·0Sector Drainer — DaaS Wallet Drainer with Phantom 0-Day Bypass·0World Cup 2026 — Stake.com Impersonation Wallet Drainer Campaign·0FTX·0LAB Token (LabsAI)·0FEMITBOT Telegram Mini App Fraud Network·0Jewelbug APT·0Fake Uniswap V4 Airdrop Phishing Network (2026)·0AscendEX — Insolvency and Withdrawal Freeze (July 2026)·0Donald Basile / Bitcoin Latinum (BTCL)·0Alameda·0Malone Lam Crypto Syndicate·0HormuzSafe Marine Services Authority / Persian Gulf Marine Insurance Company (PGMIC)·0SafeMoon·0Movement Labs·02026 Violent Crypto Wrench Attack Wave — H1 Chainalysis Report·0Rushi Manche·0MiCA Non-Compliant Exchange Risk Cluster (Post-July 1, 2026)·0Forsage / Olena Oblamska·0Centra Tech·0Quark Drainer·0DSJEX / BG Wealth Sharing Ponzi·0Mass Address Poisoning Campaign (Ethereum 2025-2026)·0Shelbit Exchange·0FIFA World Cup 2026 Crypto Phishing and Typosquatting Infrastructure·0DOJ $25M Crypto Forfeiture International Fraud Rings (July 2026)·0Sinaloa Cartel — OFAC Ethereum Address Designations·0AscendEX (BitMax)·0Holoworld AI — AVA Token Insider Bundling Scheme·0Morocoin / Berge Blockchain / Cirkor / AI Wealth Investment Club Network·0MiCA Post-Deadline Crypto Firm Impersonation Scam Cluster — August 2026·0Heisenberg Guru (HSBG)·0Squid Game Token·0FIFA World Cup 2026 Crypto Streaming Scam Network·0Cream Finance·0IRS Fake Digital Asset Compliance Portal — Physical Mail Phishing·0CREAM Lending·0Miloud Abderrahmane (ISIS Crypto Facilitator)·1StableMagnet·2Socket Security Malicious Browser Extension Campaign August 2026·2HQI Exchange·2Jonathan Spalletta — Uranium Finance Exploiter·2Google Coin / Fake Gemini AI Chatbot Presale Scam·2Blur Finance·2TurtleDex·2Gotbit·2Squid Games (SQUID Token)·2Arbix Finance·2Do Kwon·2Huione Group·2Jonathan Spalletta·2OLPC / BnbLabubu Token (PancakeSwap Pool Exploit)·2RaveDAO·2Fake Chainbase Airdrop Phishing Campaign·2Transit Finance·2Luna Yield·2Siavash Kayvanpour — OFAC-Designated Shelbit Founder·2Save the Kids Token·2Veer Chetal·2Forsage·2RiskOnBlast·2Torque Trading·2TurtleDex·2Blessed Trust & Hexa Whale·2Kokomo Finance·2Bitcoin Latinum (LTNM) / Donald Basile·2FCoin·3TesseraDAO TSR Token Unauthorized Mint Exploit·3Sahil Arora·3RaveDAO (RAVE Token)·4LAB Token (Smartliquid AI)·4AscendEX Exchange·4DxSale·4LAB Token·4Crypto Beast (ALT Token Influencer)·4LML/USDT staking protocol·4SKP / Skippy Token·4CLS Global FZC / ZM Quant Investment·4Bald·4LAB Token (AI Terminal / Vova Sadkov)·4Merlin DEX·4Meerkat Finance·4DogWifTools·4Ashcrypto — ROYA Token Pump-and-Dump·4Crypto Beast·4Harmony Horizon Bridge·4Uranium Finance·4BlockDAG Network·4Balance Coin (BLC) Oracle Manipulation / 42DAO·4Venus Protocol THE Token Flash-Loan Exploit (March 2026)·5Web3Port·5JELLY·5WallStreetBets·5MERLIN DEX·50x327a81d0d128db8886d265be73c9fdda97194f30·5Nobitex·5Ooki Protocol·5Sportsbet·6Bitpapa Exchange·6Allbridge Core Second Flash-Loan Exploit (July 2026)·6CryptoZoo·6Huobi / HTX·7Terra 2.0·7TartSwap (TART, Solana mint 6MXygsP9QDJiEqGCuHjbsru6vU1YmtynDWnTsx6uWbTv)·7H1 2026 Crypto Project Shutdown Wave (100+ Projects)·7Roberto Zibert·8LULA Token (BSC Reserve Manipulation Exploit)·8Poolin Technology·8C&M Software·8Harmony ONE (Protocol Entity)·8ValueDefi·8Allbridge Core — CCTP Base Chain Exploit (August 2026)·8Humanity Protocol June 2026 Exploit·8Allbridge Core — Second Flash Loan Exploit via Same Unpatched Vector·8James Wynn·8Wanchain-Cardano Bridge NIGHT Token Exploit (July 2026)·8pump.fun·8Changpeng Zhao·8Trove Markets·8$TRUMP Memecoin — Presidential Conflict of Interest and Retail Losses·8SUNRAY·FINANCE·8SIREN Token·9BitMart Exchange Shutdown 2026·9MemeCore (M Token)·9MANTRA Chain·10BitMEX (2026 Class Action — Insider Trading and Liquidation Fraud)·10Qubit Finance·10Curio·10Bunny Finance·10Blizz Finance·10Sheldon Xia (BitMart Founder)·10EasyFi·10Mixin Network·10Polter Finance·10GDAC·10Little Boy Plus - BSC DeFi Logic Exploit·10Abracadabra Spell·10Radiant V2·10Swan Treasury (STY Token)·10HTX FCA UK Enforcement — Illegal Crypto Promotions (2026)·10Iron Finance·10Multichain·10Elephant Money·10PolyNetwork·10Poly Network·10Binance Bridge·10Harmony Bridge·10Badger DAO·10Odin.fun·10Dego Finance·10BearnFi·12Bidao·12Joaquin Diaz (Orionx Co-Founder)·12Masa·12Gym Network·12PlayDapp·12Popsicle Finance·12Solareum·12Atlantis Loans·12BSC TMM/USDT·12Tapioca DAO·12XBridge·12MELANIA Memecoin·12bZx Protocol·12Waygu / Wagyu·12DeFi100·12LND·12Cypher Protocol·12CodexField·12Fortress Protocol·12pNetwork·12Spartan Protocol·12Humanity Protocol H Token Hack·13Rainberry Inc·13Pi Network (PI)·14Loopring DEX — Trustless Exit Disabled at Shutdown·14Garden Finance·14Allbridge Core Solana Flash Loan Exploit (July 2026)·14Ionic Money·14Terence Kwok — Humanity Protocol Staged Hack·14AutoShark Finance·14BNB Chain Bridge·16Levyathan·18FOMO Token·18PancakeBunny·18BounceBit L1 Exploit and Chain Shutdown (August 2026)·18MiCA EU Mass Non-Compliance — 83% Unlicensed Platform Risk·18Dexible V2·18Fantasm Finance·18Cetus CLMM·18Alpha Finance Lab·18Noones·18LaunchZone·18Cover Protocol·18WAYGU CASH·18Transit Swap·18Alephium Bridge·18Ionic Protocol·18Baton Corporation (Pump.fun)·18DLMC Token (BNB Chain Flash Loan Exploit)·18HyPC·18MAP Protocol·18Humanity Protocol June 2026 Hack·18Tectonic Protocol·18Humanity Protocol - Staged Hack Allegation (ZachXBT)·18Mobius Token·18BUILDon·18Fortress Loans·18LendHub·18Frontier (FRONT)·18Gary Wang·18Paraluni Masterchef·18TRUMP Official Memecoin ($TRUMP)·18MANTRA (OM Token)·18Siren (SIREN)·18Value DeFi Protocol·18EasyFi Network·18RIVER Token·18ForceBridge·20GraceToken·20DuelBits·20B-Squared Network·20Philippines SEC — Multi-Exchange Unlicensed Operations Enforcement·20Pepe (PEPE)·20BounceBit·20Binance (Law Enforcement Cooperation Rollback)·20BurgerSwap·22EdgeX / EDGE Token·22Gravity Bridge·22DAO Maker Vesting·22Syscoin Bridge·22XT Exchange·22RocketSwap Base·22Renzo·22Africoin·22MYX Finance·22Bondly·22ApeRocket·22SurgeBNB·22Palmswap·22MSCST (MSC Protocol)·22INK Finance·22Hunter Biden ($LAPTOP token)·22Smoking·22FEGex·22TAC Chain·22ChainSwap·22Sheldon Xia·22MemeCore·22Local Traders·22Odin.Fun·22Ronin Network·22World Liberty Financial (WLFI)·22Ice Open Network (ICE)·22Harvest Finance·22Punk Protocol·22B² Network·23Aster (ASTER)·23Goatseus Maximus (GOAT)·23Hyperbridge (Polkadot-Ethereum Bridge) — April 2026 Exploit·24ALEX Lab·24Binance - MiCA Greece Application Withdrawal·25HTX (Huobi) Exchange·25SuperFarm / SuperVerse·25Cronos Chain·26BullX·27Sirio Finance·28Orion Pools·28Superfortune AI (GUA)·28Boop (boop.fun)·28Pike Finance·28Nesa (NES)·28TAC Network·28Growth DeFi·28Mixin Network·28Moola Market·28BtcTurk·28Renzo Protocol·28Mars Perps·28OlaXBT·28Ankr & Helio Protocol Hack·28Portal·28GriffinAI·28Kronos Research·28GMX V1 Perps·28KyberSwap Classic·28GemPad·28Harbor Protocol·28Aperture LM·28Allbridge·28Bridgers Cross-Chain Swap·28Cosmos Labs·28Ola Finance·28CrossCurve Bridge·28Level Finance·28USDD·28Edel Finance·28Trust Wallet Chrome Extension Hack (December 2025)·28Bitfinex / Tether·28Matcha Meta·28ACT·28Thorchain DEX·28Slope Wallet·28Seedify·28Venus Core Pool·28MiCA Transitional Period Expiry — Unlicensed EU Crypto Platforms·28BinanceLife (币安人生)·28Platypus Finance·28edgeX Exchange·28Syscoin·28Belt Finance·28BitMEX Exchange Closure September 2026·28Meter Passport Bridge·28Spartan Protocol·28Symbiosis Finance BridgeV2 syBTC Exploit (September 2026)·30Evmos Network·30Loopring DEX Shutdown (June 2026)·30Falcon USD (USDf)·30KAITO·30Nexera·32PiggyBank Protocol·32ChangeNOW·32TempleDAO·32Blend Pools V2·32Eleven Finance·32Goose Finance·32Treasure (TreasureDAO)·32Roll·32uniBTC·32JUST·32KiiChain·32CoinEx·32Wanchain·32Unizen·32Symbiosis Finance (BTC Bridge Exploit)·32Zircon Gamma·32BingX·32KuCoin Exchange Hack·32Hyperbridge·32Saga·32Apyx Finance (apxUSD)·32Banana Gun·32Audiera (BEAT)·32LiFi Finance·32Aldrin·32Saga EVM Blockchain·32Midas Capital·32Neutrl·33United Stables (U)·33Alephium·34Bitget Exchange (Shawn Liu)·34Hyperdrive HL·35Kiln·35Aethir·36Cod3x·36Stake DAO·36Dogwifhat (WIF)·38MONA (Monavale / DIGITALAX)·38Fogo·38Astera.fi·38Axie Infinity·38Symbiosis Finance·38IoTeX·38WazirX·38THORChain GG20 MPC Vault Exploit (May 2026)·38USD1 (World Liberty Financial)·38Unilend V2·38four.meme·38Evoq Finance·38KiloEx·38Ankr (ankrFLOW Collateral Exploit)·38Port3 Network·38LiFi Protocol·38Hyperbridge (Polkadot-Ethereum Bridge)·38SolvBTC·38Veil Cash·38Stake.com·38Save·38Superfluid·38Grass·38KAT katana-network·39yg·39BFUSD·40Railgun·40Jump Trading·42SafePal·42Fantom (Sonic Labs)·42Orion Protocol·42DGLD·42Midnight Network / NIGHT Token·42Allbridge Core·42Cosmos (ATOM)·42Usual USD0·42GooseFX·42Granary Finance (GRAIN)·42Hacken Token·42Across Protocol·42GMGN.ai·430G Labs·43Polygon (POL)·44Midnight (NIGHT Token)·44OKX·44Binance·45Maestro·47Aptos·50Taptaptap·50Zcash·500xf2E8ec859f63aB5a1F51B4B88300707169f68745·50Clober Liquidity Vault·52PeopleDAO·52THORChain·52Arbitrum·52Fomo (fomo.family)·52Algorand·52Frax Finance·52USX·52Zabu Finance·52Ronin Bridge·52PayPal USD (PYUSD)·53Robinhood Crypto·54Celestia·54Loopring·54Polygon·54Ethena·55Trust Wallet·55USDS·55Filecoin·55Injective Protocol·55Global Dollar (USDG)·56Allo Protocol·57Sei Network·58Synthetix·58Linea·58Scroll·58Ethena·58Spicenet·58Cosmos Hub·58Ankr·58Monero·58Playsomo·60Ondo US Dollar Yield (USDY)·60Convex Finance·62PAX Gold (PAXG)·62LayerZero Executor Wallet Incident (July 2026)·62Matcha·62Spark Protocol·621inch·62Wormhole·62Circle·62Kaspa·64Safe{Wallet}·68Dialect·69Lido Finance·70Ondo Finance·72Bybit·72Circle USYC·73Kamino Finance·74BlackRock USD Institutional Digital Liquidity Fund (BUIDL)·82ZachXBT·82
- □Amazonorganizationalso inNicolo Nourafchan / Robert Yadgarov (SEC/DOJ Insider Trading Ring)·0Faris Ali / UK Crypto Home Invasion Ring·0Faris Ali·2GAW Miners / Josh Garza·2Mining Automatic (Zan Shaikh / Bright Vision Distribution LLC)·2Unicoin Inc.·4Grand Base·5Saddle Finance·10MELANIA Memecoin·12ShipMonk·16Term Labs·17Term Finance·22Roman Storm·22YO Protocol·42CoW Swap (CoW Protocol)·50HEEBOO·54Injective Protocol·55Scroll·58ThalaSwap·62Amazon·65Amazon Web Services·65Crossmint·70Orca·80
Timeline(9 events)
August 2023
ClearFake campaign begins using EtherHiding technique on BNB Smart Chain, storing malicious payload JavaScript inside on-chain smart contracts. Guardz researchers later document this as the first known EtherHiding campaign.
The Hacker News16 October 2023
The Hacker News and Guardz publicly document the EtherHiding technique for the first time, describing it as 'the next level of bulletproof hosting' and attributing it to the ClearFake campaign targeting WordPress sites.
The Hacker NewsOctober 2025
Google Threat Intelligence Group (GTIG) reports that DPRK-linked threat actor UNC5342 has adopted the EtherHiding technique in fake job interview social engineering campaigns targeting software developers, marking the first documented nation-state use of the technique.
Google Cloud BlogFebruary 2026
CryptoBandits malware campaign begins activity, distributing clipboard-hijacking and USB-worm components via malicious .lnk payloads. Microsoft later identifies the campaign as active from at least February 2026.
Microsoft Security BlogApril 2026
Researchers discover the Omnistealer campaign using TRON, Aptos, and BNB Chain blockchains for on-chain payload delivery to steal credentials, cloud account data, passwords, and cryptocurrency wallet contents, demonstrating multi-chain expansion of the EtherHiding model.
Decrypt17 June 2026
Microsoft Security Blog publicly discloses the CryptoBandits malware: a clipboard hijacker polling every 500 milliseconds for cryptocurrency wallet addresses, propagating via USB worm, and routing C2 traffic through Tor. Trojan:Win32/CryptoBandits.A detection name assigned.
Microsoft Security Blog7 August 2026
Microsoft Threat Intelligence publicly discloses the active ClickFix + EtherHiding + BNB Chain campaign, stating it targets thousands of enterprise and consumer Windows devices globally every day. Payloads identified include Lumma Stealer, XWorm, AsyncRAT, and MintsLoader. Detections Trojan:Win32/ClickFix.* and Trojan:Win32/TermFix.* named.
crypto.news / Decrypt / Crypto Economy7 August 2026
Huntress researchers separately document a Go-based macOS infostealer delivered via ClickFix attacks, capable of partially redirecting cryptocurrency transactions without fully emptying wallets to evade detection.
The Hacker News8 August 2026
The Hacker News reports over 250 ClickFix domains using browser fingerprinting to serve platform-specific macOS malware lures, indicating campaign infrastructure has scaled to hundreds of distinct lure domains.
The Hacker NewsDecision Log
- hash: 9gfDvhiR6skMXg9W2TGeCKhv8xC1njsiMH4HxxSqLmCv
- hash: 8s82sazRYJftjNj8Pwz3aZ2ZrbsY4G8DSLpbcGMnQbTP
- hash: aQcz63gjyRNyFk1YRVhqNeySMjwCrE5WN7BtY4m9RGM
This investigation is cryptographically anchored to the Solana blockchain (3 events). 17 of 18 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/8/2026, 11:15:55 PM
last updated: 8/10/2026, 1:14:52 PM
5 viewsavoid.net — verified advice for a post-truth world