TechNewsReel
Live

Cybercriminals Use BNB Smart Chain to Deliver 'ClickFix' Malware to 5,400 Sites

Attackers are leveraging blockchain smart contracts to host malicious loaders that trick users into manually installing malware.

TechNewsReel Newsroom · September 5, 2026

Cybercriminals have compromised more than 5,400 small-business websites to deploy a sophisticated social engineering campaign known as 'ClickFix.' The operation marks a significant shift in malware delivery by using decentralized blockchain infrastructure to host malicious payloads, making the campaign exceptionally difficult for security teams to dismantle.

According to reports from BleepingComputer and AnChain.AI, the attackers primarily targeted small businesses utilizing WordPress or PrestaShop. Once a visitor lands on a compromised site, they are presented with a fake CAPTCHA overlay or a technical error message. This lure tricks the user into manually copying and pasting a malicious command into the Windows Run dialog or the macOS Terminal, effectively turning the victim into the execution mechanism for the malware.

The Blockchain Infrastructure

To ensure high takedown resistance and low operational costs, the campaign leverages the BNB Smart Chain (BSC) testnet. Unlike traditional malware that relies on centralized virtual private servers (VPS) or bulletproof hosting, this campaign uses a three-tier smart contract model to manage its operations.

As detailed by AnChain.AI, the system begins with a 'Root Router' contract that detects the visitor's operating system. It then directs the user to OS-specific 'Payload' contracts that serve the social engineering lure. Finally, a 'Tracking Registry' contract is used to record victim UUIDs directly on the blockchain. This setup allows the operator to update what every compromised site delivers by modifying a single contract, ensuring all visitors retrieve the latest version upon the next page load.

Why It Matters

This fusion of Web2 intrusion and Web3 infrastructure creates a delivery system that is nearly impossible for traditional domain registrars or hosting providers to take down, as the 'dead drop' exists on an immutable ledger.

Furthermore, the 'ClickFix' technique is designed to bypass traditional automated security controls. Because the malicious activity is initiated by the user manually pasting a command, many endpoint detection and response (EDR) tools may view the action as legitimate user behavior rather than an external exploit. This renders standard software-based defenses ineffective against the initial infection vector.

What's Next

Security researchers are now monitoring for further evolutions in 'EtherHiding'—the practice of hiding command-and-control (C2) infrastructure within blockchain networks. While the core mechanism of the ClickFix campaign has been identified, the use of decentralized ledgers suggests that future campaigns may move entirely away from centralized infrastructure. Organizations are advised to educate employees on the dangers of pasting unknown commands into system terminals, regardless of the prompts provided by a website.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.