Security researchers and Italy’s national cyber agency warned of active ClickFix and TerminalFix malware campaigns that trick users into manually launching malicious Windows commands from fake CAPTCHA or verification pages. The activity relies on compromised legitimate websites, including WordPress sites, where obfuscated JavaScript redirects visitors to prompts telling them to open Run, Windows Terminal, or PowerShell and paste attacker-supplied commands. Those commands abuse trusted Windows utilities such as powershell.exe, cmd.exe, mshta.exe, rundll32.exe, msiexec.exe, curl.exe, WMI, WebDAV, and scheduled tasks to download follow-on payloads, establish persistence, and contact attacker infrastructure.
Researchers said the operators are using EtherHiding to conceal parts of their delivery chain inside smart contracts on public blockchains, including BNB Smart Chain and Polygon, which are queried through RPC gateways to retrieve configuration or malicious instructions. WatchGuard linked one cluster to the ErrTraffic malware-as-a-service operation and reported delivery of payloads including Vidar, Okobot, ClipBanker variants, BabaDedaLoader, Node.js backdoors, OnionDrop-related malware, and LegionLoader-linked samples. The campaign is aimed at credential theft, browser and cookie harvesting, cryptocurrency-wallet theft, defense evasion, lateral movement, and staging for broader compromise, prompting defenders to tighten command-line controls, increase PowerShell and endpoint monitoring, isolate affected hosts, and reset exposed accounts.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
WatchGuard linked the ErrTraffic activity to a malware-as-a-service operation advertised by a forum user known as LenAI. The operation was observed distributing multiple payload families including Vidar, Okobot, LegionLoader-linked malware, OnionDrop-related payloads, Node.js backdoors, and BabaDedaLoader.
WatchGuard analysts identified an active malware delivery campaign tracked as ErrTraffic that uses compromised WordPress sites and ClickFix-style fake verification prompts to trick users into running malicious Windows commands. The campaign retrieves smart-contract-based configuration from the Polygon blockchain via RPC services, allowing operators to rotate infrastructure without updating every compromised site.
Microsoft Threat Intelligence identified a malware campaign that evolves the ClickFix and TerminalFix social-engineering techniques by storing malicious instructions in smart contracts on the BNB Smart Chain and retrieving them through blockchain RPC gateways. The campaign uses compromised legitimate websites, fake CAPTCHA or verification pages, and user-executed Windows commands to deliver follow-on malware.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourceacn.gov.it
Open sourcecertego.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.