ClickFix BNB Chain EtherHiding Malware Campaign
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·4FL9c9…nCiESummary
An active malware campaign, publicly disclosed by Microsoft Threat Intelligence on August 7, 2026, combines ClickFix-style fake CAPTCHA social engineering with the EtherHiding technique to store malicious payload instructions inside BNB Smart Chain smart contracts. Because the payload hosting is on-chain and can only be modified by the deployer's private key, traditional DNS and hosting takedowns are ineffective against the attack infrastructure. Deployed payloads include information stealers, remote access trojans, and a crypto clipboard hijacker (CryptoBandits) that silently replaces copied wallet addresses with attacker-controlled ones every 500 milliseconds.
Connected Entities
1 entitiesTimeline(9 events)
August 2023
ClearFake campaign begins using EtherHiding technique on BNB Smart Chain, storing malicious payload JavaScript inside on-chain smart contracts. Guardz researchers later document this as the first known EtherHiding campaign.
The Hacker News16 October 2023
The Hacker News and Guardz publicly document the EtherHiding technique for the first time, describing it as 'the next level of bulletproof hosting' and attributing it to the ClearFake campaign targeting WordPress sites.
The Hacker NewsOctober 2025
Google Threat Intelligence Group (GTIG) reports that DPRK-linked threat actor UNC5342 has adopted the EtherHiding technique in fake job interview social engineering campaigns targeting software developers, marking the first documented nation-state use of the technique.
Google Cloud BlogFebruary 2026
CryptoBandits malware campaign begins activity, distributing clipboard-hijacking and USB-worm components via malicious .lnk payloads. Microsoft later identifies the campaign as active from at least February 2026.
Microsoft Security BlogApril 2026
Researchers discover the Omnistealer campaign using TRON, Aptos, and BNB Chain blockchains for on-chain payload delivery to steal credentials, cloud account data, passwords, and cryptocurrency wallet contents, demonstrating multi-chain expansion of the EtherHiding model.
Decrypt17 June 2026
Microsoft Security Blog publicly discloses the CryptoBandits malware: a clipboard hijacker polling every 500 milliseconds for cryptocurrency wallet addresses, propagating via USB worm, and routing C2 traffic through Tor. Trojan:Win32/CryptoBandits.A detection name assigned.
Microsoft Security Blog7 August 2026
Microsoft Threat Intelligence publicly discloses the active ClickFix + EtherHiding + BNB Chain campaign, stating it targets thousands of enterprise and consumer Windows devices globally every day. Payloads identified include Lumma Stealer, XWorm, AsyncRAT, and MintsLoader. Detections Trojan:Win32/ClickFix.* and Trojan:Win32/TermFix.* named.
crypto.news / Decrypt / Crypto Economy7 August 2026
Huntress researchers separately document a Go-based macOS infostealer delivered via ClickFix attacks, capable of partially redirecting cryptocurrency transactions without fully emptying wallets to evade detection.
The Hacker News8 August 2026
The Hacker News reports over 250 ClickFix domains using browser fingerprinting to serve platform-specific macOS malware lures, indicating campaign infrastructure has scaled to hundreds of distinct lure domains.
The Hacker NewsDecision Log
- hash: 9gfDvhiR6skMXg9W2TGeCKhv8xC1njsiMH4HxxSqLmCv
- hash: 8s82sazRYJftjNj8Pwz3aZ2ZrbsY4G8DSLpbcGMnQbTP
- hash: aQcz63gjyRNyFk1YRVhqNeySMjwCrE5WN7BtY4m9RGM
This investigation is cryptographically anchored to the Solana blockchain (3 events). 17 of 18 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/8/2026, 11:15:55 PM
last updated: 8/10/2026, 1:14:52 PM
5 viewsavoid.net — verified advice for a post-truth world