The attack unfolds in a relatively short sequence of steps that exploit user trust and built-in Windows tools:
To avoid detection, attackers extensively abuse legitimate, built-in Windows components—a technique known as "living-off-the-land" (LOLBins) . The tools observed in this campaign include:
By using these trusted Microsoft components, attackers can bypass many traditional endpoint defenses .
This campaign is not limited to a single piece of malware. It serves as a delivery mechanism for a range of information-stealing and remote-access trojans :
Successful execution can lead to credential exposure, establishing persistent access, lateral movement within a network, and eventual ransomware deployment . On macOS systems, the campaign has also been observed delivering MacSync and Atomic Stealer
.
While the public advisory from Microsoft did not provide an exhaustive list of specific Microsoft Defender Antivirus detection names for this particular campaign , related security research from July and August 2026 indicates that Microsoft Defender for Endpoint provides behavioral coverage for
:
The macOS ClickFix blog published by Microsoft on August 5, 2026, documented that Microsoft Defender for SmartScreen blocks the malicious webpage, and Defender XDR provides surface coverage under specific tactic and technique mappings . Microsoft Defender Antivirus detections for the broader ClickFix threat family include names such as
Behavior:Win32/ClickFix, Trojan:Win32/ClickFix, and Trojan:HTML/FakeCaptcha , though specific signatures for this campaign's BNB Chain-related JavaScript injections are deployed but were not individually named in the public warning
.