Security researchers and Italy’s national cyber agency warned of active ClickFix and TerminalFix malware campaigns that trick users into manually launching malicious Windows commands from fake CAPTCHA or verification pages. The activity relies on compromised legitimate websites, including WordPress sites, where obfuscated JavaScript redirects visitors to prompts telling them to open Run, Windows Terminal, or PowerShell and paste attacker-supplied commands. Those commands abuse trusted Windows utilities such as powershell.exe, cmd.exe, mshta.exe, rundll32.exe, msiexec.exe, curl.exe, WMI, WebDAV, and scheduled tasks to download follow-on payloads, establish persistence, and contact attacker infrastructure.
Researchers said the operators are using EtherHiding to conceal parts of their delivery chain inside smart contracts on public blockchains, including BNB Smart Chain and Polygon, which are queried through RPC gateways to retrieve configuration or malicious instructions. WatchGuard linked one cluster to the ErrTraffic malware-as-a-service operation and reported delivery of payloads including Vidar, Okobot, ClipBanker variants, BabaDedaLoader, Node.js backdoors, OnionDrop-related malware, and LegionLoader-linked samples. The campaign is aimed at credential theft, browser and cookie harvesting, cryptocurrency-wallet theft, defense evasion, lateral movement, and staging for broader compromise, prompting defenders to tighten command-line controls, increase PowerShell and endpoint monitoring, isolate affected hosts, and reset exposed accounts.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
WatchGuard linked the ErrTraffic activity to a malware-as-a-service operation advertised by a forum user known as LenAI. The operation was observed distributing multiple payload families including Vidar, Okobot, LegionLoader-linked malware, OnionDrop-related payloads, Node.js backdoors, and BabaDedaLoader.
WatchGuard analysts identified an active malware delivery campaign tracked as ErrTraffic that uses compromised WordPress sites and ClickFix-style fake verification prompts to trick users into running malicious Windows commands. The campaign retrieves smart-contract-based configuration from the Polygon blockchain via RPC services, allowing operators to rotate infrastructure without updating every compromised site.
Microsoft Threat Intelligence identified a malware campaign that evolves the ClickFix and TerminalFix social-engineering techniques by storing malicious instructions in smart contracts on the BNB Smart Chain and retrieving them through blockchain RPC gateways. The campaign uses compromised legitimate websites, fake CAPTCHA or verification pages, and user-executed Windows commands to deliver follow-on malware.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 52 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourceacn.gov.it
Open sourcecertego.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.