Microsoft Warns of ClickFix Malware Using Blockchain to Hide Attack Instructions
Microsoft has issued a warning about a malware campaign known as ClickFix, which is infecting thousands of devices every day. What makes this campaign notable is its use of BNB Chain smart contracts—a blockchain technology—to fetch and store the instructions used in the attack.
By hiding attack commands within blockchain smart contracts, attackers make it harder for security tools to detect and block the malicious activity, since blockchain data is decentralised and not easily taken down like a traditional malicious website. ClickFix-style attacks typically trick users into copying and running malicious commands themselves, often through fake error messages or verification prompts.
While the technical details are complex, the practical risk for small businesses is simple: employees can be tricked into running harmful commands on their own computers, giving attackers a foothold without needing to breach any network defences directly.