Microsoft Warns Hackers Are Exploiting BNB Chain to Distribute Malware

Hackers exploit BNB Chain
Table of Contents

TL;DR:

  • Injection into legitimate sites: Attackers compromise third-party websites to insert malicious JavaScript code that communicates with the blockchain.
  • Resilience to takedowns: The malicious infrastructure uses smart contracts on BNB Smart Chain, making unilateral removal of content by third parties impossible.
  • Coordinated social engineering: The scheme combines fake CAPTCHAs with the ClickFix trick to induce the victim to execute malicious commands in the system console.

Microsoft Threat Intelligence issued a report on a new campaign in which hackers exploit BNB Chain to store and distribute malicious code. According to researchers, cybercriminals compromise legitimate websites and inject JavaScript scripts that connect with smart contracts hosted on the BNB Smart Chain network.

Integration with the BNB Smart Chain network

According to data from Microsoft Threat Intelligence, the operation leverages the technique known as EtherHiding, a strategy linked to the ClearFake malware group. In this process, the malicious script obtains the next layer of the payload through a BNB Smart Chain RPC node.

Technical analyses indicate that this decentralized design makes the attacker’s network significantly more invulnerable to traditional removal or governmental takedown attempts. Official data reveals that content recorded in the smart contract can only be edited or removed by the private key of the wallet owner who deployed it.

To finalize the infection on the end device, the campaign employs a browser interface-based social engineering technique. Cybercriminals present users with a fake CAPTCHA designed to manipulate the victim.

Hackers exploit BNB Chain

The visible instructions ask the visitor to open the Windows “Run” command window, paste the text previously stored in the clipboard, and process the attacker’s order. The cybersecurity firm warns that the attack code hides its components through complex obfuscation techniques while abusing native operating system tools, such as PowerShell, Command Prompt, Windows Terminal, mshta, and curl.

If the victim completes the execution process, the infected system becomes exposed to the deployment of diversified harmful software, including Lumma Stealer, XWorm, AsyncRAT, and MintsLoader. According to the technical warning, successful breaches allow massive credential extraction and pave the way for manually operated ransomware attacks.

Given the increase in these modalities, the cybersecurity team recommended that organizations restrict unnecessary command-line utilities and enable detailed PowerShell logging.

This alert joins a series of previous notifications issued by the company within the cryptographic ecosystem. In June of last year, Microsoft disclosed details about a “crypto clippers” campaign designed to modify wallet addresses copied to the clipboard. Months earlier, the research team revealed a large-scale cryptojacking network that combined SEO poisoning techniques, demonstrating constant evolution in threats targeting decentralized digital environments.

RELATED POSTS

Ads

Follow us on Social Networks

Crypto Tutorials

Crypto Reviews