The campaign relies on deceptive browser-based CAPTCHA pages to trick users into executing attacker-supplied commands. When a victim interacts with these prompts, they are instructed to open the Windows Run dialog or PowerShell and paste obfuscated script content. Once executed, this triggers a sequence that pulls further malicious payloads from the blockchain, granting attackers a foothold on the target system.
Microsoft Threat Intelligence researchers note that this method is particularly persistent because the smart contract contents can only be modified by the wallet owner. By integrating these blockchain-based instructions with social engineering tactics—such as the similar TerminalFix lure—threat actors are deploying a variety of malicious tools, including Lumma Stealer, Xworm, and AsyncRAT. These infections often serve as a gateway for credential theft, lateral network movement, and the deployment of human-operated ransomware.
To mitigate these threats, security teams are advised to restrict user access to Windows command-line tools and enforce strict application control policies. Microsoft Defender now includes specific detections for this activity, such as Trojan:Win32/ClickFix and Trojan:Win32/TermFix. Organizations that trigger these alerts are encouraged to isolate affected endpoints immediately to prevent broader network compromise.

Comments (0)
No comments yet. Be the first!