The campaign relies on deceptive browser-based CAPTCHA pages to trick users into executing attacker-supplied commands. When a victim interacts with these prompts, they are instructed to open the Windows Run dialog or PowerShell and paste obfuscated script content. Once executed, this triggers a sequence that pulls further malicious payloads from the blockchain, granting attackers a foothold on the target system.
Microsoft Threat Intelligence researchers note that this method is particularly persistent because the smart contract contents can only be modified by the wallet owner. By integrating these blockchain-based instructions with social engineering tactics—such as the similar TerminalFix lure—threat actors are deploying a variety of malicious tools, including Lumma Stealer, Xworm, and AsyncRAT. These infections often serve as a gateway for credential theft, lateral network movement, and the deployment of human-operated ransomware.

Comments (0)
No comments yet. Be the first!