Microsoft Threat Intelligence uncovers sophisticated ClickFix campaigns that embed malicious commands in blockchain smart contracts and employ browser fingerprinting to target Windows and macOS users, complicating detection and takedown efforts.
Microsoft has warned that ClickFix campaigns are becoming harder to disrupt as attackers increasingly hide their instructions inside blockchain smart contracts and use browser fingerprinting to separate real victims from security researchers. The latest findings show the technique spreading across both Windows and macOS, with operators adapting their delivery methods to bypass takedowns and frustrate analysis.
According to Microsoft Threat Intelligence, one Windows-focused cluster uses EtherHiding, a method that stores malicious commands in smart contracts on the BNB Smart Chain. Compromised websites load Base64-encoded JavaScript that queries those contracts through RPC gateways and retrieves the next stage of the attack. Because the payload lives on-chain, removing the code is not as simple as taking down a server; only the wallet that deployed the contract can change its contents.
Victims are then shown fake CAPTCHA checks that push them to open the Windows Run dialogue and paste attacker-controlled commands. Microsoft said the chains commonly abuse built-in tools such as PowerShell, mshta, rundll32, msiexec and curl, often using obfuscation to conceal what the commands are doing. The company said the campaigns reach thousands of enterprise and consumer devices worldwide each day and have delivered malware including Lumma Stealer, Xworm, AsyncRAT and MintsLoader.
On macOS, Microsoft has tracked a separate ClickFix cluster that now hides malicious terminal commands behind server-side fingerprinting checks. The operation spans more than 250 domains, many using algorithmic names. The first page a visitor sees collects browser details, WebGL signals, timezone data and iframe context, then decides whether to serve a lure or a harmless decoy. Microsoft said genuine macOS users are shown a fake “Verified Publisher” download page, while sandboxes, virtual machines and non-macOS browsers are often given blank or benign content.
The company said this selective delivery makes the campaign more difficult to detect at scale and helps it push information-stealing malware such as MacSync and Atomic Stealer. Microsoft said the broader ClickFix threat family has already evolved from simple social engineering into a more flexible delivery system that can be repurposed across platforms, infrastructure types and malware payloads.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





